作者
Yevgeniy Dodis, Paul Grubbs, Thomas Ristenpart, Joanne Woodage
发表日期
2018
研讨会论文
Advances in Cryptology–CRYPTO 2018: 38th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 19–23, 2018, Proceedings, Part I 38
页码范围
155-186
出版商
Springer International Publishing
简介
Message franking enables cryptographically verifiable reporting of abusive messages in end-to-end encrypted messaging. Grubbs, Lu, and Ristenpart recently formalized the needed underlying primitive, what they call compactly committing authenticated encryption (AE), and analyze security of a number of approaches. But all known secure schemes are still slow compared to the fastest standard AE schemes. For this reason Facebook Messenger uses AES-GCM for franking of attachments such as images or videos.
We show how to break Facebook’s attachment franking scheme: a malicious user can send an objectionable image to a recipient but that recipient cannot report it as abuse. The core problem stems from use of fast but non-committing AE, and so we build the fastest compactly committing AE schemes to date. To do so we introduce a new primitive, called encryptment, which captures …
引用总数
20172018201920202021202220232024116614233215
学术搜索中的文章
Y Dodis, P Grubbs, T Ristenpart, J Woodage - Advances in Cryptology–CRYPTO 2018: 38th Annual …, 2018