著者
Takanori Isobe Ryoma Ito Kazuhiko Minematsu
出版者
Information Processing Society of Japan
雑誌
Journal of Information Processing (ISSN:18826652)
巻号頁・発行日
vol.31, pp.523-536, 2023 (Released:2023-09-15)
参考文献数
55

This paper summarizes our cryptanalysis results on real-world End-to-End Encryption (E2EE) schemes published in recent years. Our targets are LINE (a major messaging application), SFrame (an E2EE protocol adopted by major video/audio applications), and Zoom (a major video communication application). For LINE, we show several attacks against the message integrity of Letter Sealing, the E2EE protocol of LINE, that allow forgery and impersonation. For SFrame, we reveal a critical issue that leads to an impersonation (forgery) attack by a malicious group member with a practical complexity. For Zoom, we discover several attacks more powerful than those expected by Zoom according to their whitepaper. Specifically, if insiders collude with meeting participants, they can impersonate any Zoom user in target meetings, whereas Zoom indicates that they can impersonate only the current meeting participants. We also describe several important works in the area of E2EE security research.

言及状況

外部データベース (DOI)

Twitter (3 users, 4 posts, 4 favorites)

LINEといえば自明な脆弱性(確かIND-CPAを満たさない認証付き共通鍵暗号)が指摘されていたような(記憶違いならゴメン)。が、流石にこれは修正されていると思う。 Forgery and Impersonation Attacks against of LINE’s End-to-End Encryption Schemes https://t.co/QUNJzDA0EY https://t.co/jKXGkpfWJJ https://t.co/kUF1VkrX44
In this special issue, an invited paper entitled "Cryptanalysis on End-to-End Encryption Schemes of Communication Tools and Its Research Trend" by Takanori Isobe, Ryoma Ito, and Kazuhiko Minematsu has been published. (open access) https://t.co/ZBCI19JyyK https://t.co/DvaBIypmj5
こちらからもダウンロード可能です。 https://t.co/XKY0KUHyjR

収集済み URL リスト