Title :
An architecture for end-to-end and inter-domain trusted mail delivery service
Author :
Ayla, Erkut Sinan ; Özgit, Attila
Author_Institution :
Havelsan Inc., Ankara
Abstract :
Common methods of e-mail delivery over the Internet is vulnerable to some significant security risks. In this study, a "trusted mail gateway" aiming at reliable and trusted end-to-end e-mail delivery is presented. The designed trusted mail gateway provides a domain with the basic security services that are message integrity, confidentiality, non-repudiation, origin authentication and availability while the message (e-mail) is being delivered through the Internet. It generates S/MIME digital signatures and performs S/MIME encryption on behalf of the domain using secret key cryptography and public-key techniques and generating cryptographic message syntax (CMS) data to provide origin authenticity, integrity and confidentiality. It applies anti-virus control and protection, spam filtering and content check to both incoming mails to the domain and outgoing mails from the domain to prevent attacks against availability. Trusted mail gateway also provides intra-domain security. It keeps e-mail messages in corresponding mailboxes as encrypted messages. Trusted mail gateway processes all the mails passing through and records processing results in a database as notary information. Moreover, it establishes trust relations with other registered trusted domains and exchanges notary information with them via a secure channel
Keywords :
Internet; digital signatures; public key cryptography; telecommunication security; unsolicited e-mail; S-MIME digital signatures; S-MIME encryption; anti-virus control; availability security service; confidentiality security service; content check; cryptographic message syntax; e-mail delivery; encrypted messages; end-to-end mail delivery service; inter-domain trusted mail delivery service; intra-domain security; message integrity security service; nonrepudiation security service; notary information; origin authentication; public-key techniques; registered trusted domains; secret key cryptography; secure channel; secure-multipurpose Internet mail extensions; security risks; spam filtering; trusted mail gateway; Authentication; Availability; Collision mitigation; Cryptography; Digital signatures; Electronic mail; Postal services; Public key; Security; Web and internet services; S/MIME; e-mail protocols; e-mail security services; inter-domain; intra-domain; notary;
Conference_Titel :
Computer Networks, 2006 International Symposium on
Conference_Location :
Istanbul
Print_ISBN :
1-4244-0491-6
DOI :
10.1109/ISCN.2006.1662537