Secure and privacy-enhanced e-mail system based on the concept of proxies

Security and privacy on the Internet and especially the e-mail, is becoming more and more important and crucial for the user. The requirements for the protection of e-mail include issues like tracking and privacy intrusions by hackers and commercial advertisers, intrusions by casual observers, and even spying by government agencies. In an expanding email use in the digital world, Internet and mobile, the quantity and sensitivity of personal information has also tremendously expanded. Therefore, protection of data and transactions and privacy of user information is key and of interest for many users. Based on such motives, in this paper we present the design and current implementation of our secure and privacy-enhanced e-mail system. The system provides protection of e-mails, privacy of locations from which the e-mail system is accessed, and authentication of legitimate users. Differently from existing standard approaches, which are based on adding security extensions to e-mail clients, our system is based on the concept of proxy servers that provide security and privacy of users and their e-mails. It uses all required standards: S/MIME for formatting of secure letters, strong cryptographic algorithms, PKI protocols and certificates. We already have the first implementation and an instance of the system is very easy to install and to use.

[1]  Matt Bishop,et al.  Computer Security: Art and Science , 2002 .

[2]  Nalini Venkatasubramanian,et al.  Delegate: A Proxy Based Architecture for Secure Website Access from an Untrusted Machine , 2006, 2006 22nd Annual Computer Security Applications Conference (ACSAC'06).

[3]  Gianmarco Baldini,et al.  An Architecture for Secure m-Commerce Applications , 2013, 2013 19th International Conference on Control Systems and Computer Science.

[4]  Ian Brown,et al.  A Proxy Approach to e-Mail Security , 1999, Softw. Pract. Exp..

[5]  David Shaw,et al.  Security of service requests for cloud based m-commerce , 2012, 2012 Proceedings of the 35th International Convention MIPRO.

[6]  Abdul Ghafoor,et al.  CryptoNET: Design and implementation of the Secure Email System , 2009, 2009 Proceedings of the 1st International Workshop on Security and Communication Networks.