You are on page 1of 10

S/MIME

SUBMITTED BY :

DIYA SHAJI
S7 ECE
ROLL NO : 22
S/MIME
● S/MIME stands for Secure/Multipurpose Internet Mail
Extensions.
● It is a universal web standard defined by the IETF.
● It is employed to encrypt MIME data.
● It facilitates email security by virtue of encryption,
authentication, and integrity.
● Protects our email data and communication through Email
Signing or S/MIME Certificate.
WHY S/MIME ?
● Installing a digital certificate blocks any attempts at
man-in-the-middle attacks.
● Even if email server has been encrypted, it still cannot
stop from stealing emails from inbox as the emails are
stored unencrypted on the servers.
● Also, it doesn’t protect when emails are in transit from
another server.
● All of these downsides can be eliminated by using an
S/MIME (client) certificate.
S/MIME CERTIFICATE
● Also known as “client certificate.”
● S/MIME can be implemented by installing an S/MIME
certificate.
● Work on the principles of public key infrastructure (PKI).
● It is similar to SSL certificate.
● The only key difference is that this certificate is installed on
clients while SSL certificate is implemented on servers.
BENEFITS OF S/MIME CERTIFICATE
● Protection from in-transit email corruption
● Protection from email spoofing
● Warns recipients
● Protects business’s reputation
● Prevents data leaks
● No repudiation
How does S/MIME certificate work?
● S/MIME certificates are based on asymmetric encryption.
So they involve two distinct keys – a public key and a
private key.
● Public key and private key come in a pair, one public key
can only have one private key and vice versa.
● The public key is actually derived from the private key.
S/MIME CERTIFICATE

EMAIL SENDER
Digital Signature

MAIL SERVER

INTERNET

MAIL RECEIVER
Signature Validation
● While using an S/MIME certificate, a sender sends an email by
encrypting it through recipient’s public key.
● The recipient decrypts the email using the private key and
there’s no scope for someone else to come in between and see
the email. This entire process is called signing.
● Signing emails removes two significant roadblocks in email
security.
● First, it takes away the likelihood of a 3rd party intervention
while the email is in transit. Second it provides authentication
to the user as the signature of the sender is attached to every
email.
COMPARISON OF PGP AND S/MIME
● PGP is designed to process plain text emails while S/MIME
allows the emails containing the multimedia files too.
● S/MIME is appropriate for industry use. As against, PGP
serves a good purpose for personal and office use.
● S/MIME is expensive as compared to PGP.
● In terms of efficiency, the S/MIME is better than the PGP
because of its centralized key management.
THANK YOU

You might also like