Welcome to the upgraded MacSphere! We're putting the finishing touches on it; if you notice anything amiss, email macsphere@mcmaster.ca

Real World Secret Leaking

dc.contributor.advisorSamavi, Reza
dc.contributor.advisorStebila, Douglas
dc.contributor.authorKnopf, Karl
dc.contributor.departmentComputing and Softwareen_US
dc.date.accessioned2019-10-07T15:27:42Z
dc.date.available2019-10-07T15:27:42Z
dc.date.issued2019
dc.description.abstractIn scenarios where an individual wishes to leak confidential information to an unauthorized party, he may do so in a public or an anonymous way. When acting publicly a leaker exposes his identity, whereas acting anonymously a leaker can introduce doubts about the information’s authenticity. Current solutions assume anonymity from everyone except a trusted third party or rely on the leaker possessing prior cryptographic keys, both of which are inadequate assumptions in real-world secret leaking scenarios. In this research we present a system called the attested drop protocol which provides confidentiality for the leaker, while still allowing leaked documents to have their origins verified. The protocol relies on identities associated with common communication mediums, and seeks to avoid having the leaker carry out sophisticated cryptographic operations. We also present two constructions of the general protocol, where each is designed to protect against different forms of adversarial surveillance. We use ceremony analysis and other techniques from the provable security paradigm to formally describe and evaluate security goals for both constructions.en_US
dc.description.degreeMaster of Science (MSc)en_US
dc.description.degreetypeThesisen_US
dc.description.layabstractWhistleblowing is an activity where an individual leaks some secrets about an organization to an unauthorized entity, often for moral or regulatory reasons. When doing so, the whistleblower is faced with the choice of acting publicly, and risking retribution or acting anonymously and risking not being believed. We have designed a protocol called the attested drop protocol, which protects the identity of the whistleblower, while allowing the unauthorized entity to have a means of verifying that the leak came from the organization. This protocol makes use of preexisting identities associated with a communication medium, such as emails, to avoid using cryptographic primitives that are impractical.en_US
dc.identifier.urihttp://hdl.handle.net/11375/25007
dc.language.isoenen_US
dc.subjectSecurityen_US
dc.subjectCryptographyen_US
dc.subjectSecret Leakingen_US
dc.subjectWhistleblowingen_US
dc.titleReal World Secret Leakingen_US
dc.title.alternativeREAL WORLD SECRET LEAKING: THE DESIGN AND ANALYSIS OF A PROTOCOL CREATED FOR THE PURPOSE OF LEAKING DOCUMENTS UNDER SURVEILLANCEen_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Knopf_Karl_H_2019September_MSc.pdf
Size:
790.82 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.68 KB
Format:
Item-specific license agreed upon to submission
Description: