International Association for Cryptologic Research

International Association
for Cryptologic Research


Paper: On the Security of a Multi-Party Certified Email Protocol

Jianying Zhou
Search ePrint
Search Google
Abstract: As a value-added service to deliver important data over the Internet with guaranteed receipt for each successful delivery, certified email has been discussed for years and a number of research papers appeared in the literature. But most of them deal with the two-party scenarios, i.e., there are only one sender and one recipient. In some applications, however, the same certified message may need to be sent to a set of recipients. In ISC'02, Ferrer-Gomila et. al. presented a multi-party certified email protocol~\cite{FPH02}. It has two major features. A sender could notify multiple recipients of the same information while only those recipients who acknowledged are able to get the information. In addition, its exchange protocol is optimized, which has only three steps. In this paper, we demonstrate some flaws and weaknesses in that protocol, and propose an improved version which is robust against the identified attacks while preserving the features of the original protocol.
  title={On the Security of a Multi-Party Certified Email Protocol},
  booktitle={IACR Eprint archive},
  keywords={applications / certified email, non-repudiation, security protocol},
  note={ 12641 received 12 Dec 2003, last revised 11 Feb 2004, withdrawn 11 Aug 2004},
  author={Jianying Zhou},