CRApr 20, 2018

SoK: Securing Email -- A Stakeholder-Based Analysis (Extended Version)

arXiv:1804.07706v33 citations
Originality Synthesis-oriented
AI Analysis

This work addresses the lack of secure, interoperable email for users, developers, and policymakers, but is incremental as it synthesizes existing knowledge without proposing new methods.

The paper analyzes the fragmented evolution of secure email solutions by examining stakeholder interests and evaluating cryptographic primitives, key management, and system designs, concluding that a universal solution is unlikely and vulnerable users are underserved.

While email is the most ubiquitous and interoperable form of online communication today, it was not conceived with strong security guarantees, and the ensuing security enhancements are, by contrast, lacking in both ubiquity and interoperability. This situation motivates our research. We begin by identifying a variety of stakeholders who have an interest in the current email system and in efforts to provide secure solutions. We then use the tussle among stakeholders to explain the evolution of fragmented secure email solutions undertaken by industry, academia, and independent developers. We also evaluate the building blocks of secure email -- cryptographic primitives, key management schemes, and system designs -- to identify their support for stakeholder properties. From our analysis, we conclude that a one-size-fits-all solution is unlikely. Furthermore, we highlight that vulnerable users are not well served by current solutions, account for the failure of PGP, and argue that secure messaging, while complementary, is not a fully substitutable technology.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes