Improved group off-the-record messaging

Improved group off-the-record messaging
复制标题

改进的群组非记录消息传递

DOI:
10.1145/2517840.2517867
复制
发表时间:
2013
期刊:
Proceedings of the 12th ACM workshop on Workshop on privacy in the electronic society
影响因子:
--
通讯作者:
Nicholas Hopper
Nicholas Hopper
中科院分区:
--
文献类型:
--
作者:
Hong Liu;Eugene Y. Vasserman;Nicholas Hopper

文献摘要

被引文献

相似文献

Off-the-Record Messaging(OTR)是一种在线的面对面私人聊天的类比--在对话时,消息是保密的,并经过身份验证,但以后不能用来证明作者身份。最初的OTR协议仅限于两方,并由多方OTR(mpOTR)扩展到群聊设置。在这样做的时候,mpOTR无意中削弱了它的两方前身提供的安全属性。我们提出了一个改进的组OTR(GOTR)协议,提供无条件的可否认性,并展示了如何获得数据源认证给定的可否认性水平。GOTR抵抗网络故障,共谋和独立的恶意内部人员,并提供高效和灵活的成员管理。我们分析了GOTR的安全属性和性能,并给出了GOTR的概念验证实现的测量结果。
Off-the-Record Messaging (OTR) is an online analogy of face-to-face private chat -- messages are confidential and authenticated at the time of the conversation, but cannot later be used to prove authorship. The original OTR protocol is limited to two parties, and is extended by multi-party OTR (mpOTR) to the group chat setting. In doing this, mpOTR unintentionally weakens the security properties provided by its two-party predecessor. We propose an improved group OTR (GOTR)protocol that provides unconditional repudiability, and show how to obtain data origin authentication given this level of repudiability. GOTR resists network failure, colluding and independent malicious insiders, and provides efficient and flexible membership management. We analyze the security properties and performance of GOTR, and present measurement results of a proof-of-concept implementation of GOTR.