Bi-Deniable Public-Key Encryption

The notion of "deniable encryption" was introduced by Julian Assange & Ralf Weinmann in the Rubberhose filesystem and explored in detail in a paper by Ran Canetti, Cynthia Dwork, Moni Naor, and Rafail Ostrovsky in 1996. An encryption scheme is deniable if the sender can generate 'fake random choices' that will make the ciphertext 'look like' an encryption of a different cleartext, thus keeping the real cleartext private. Analogous requirements can be formulated with respect to attacking the receiver and with respect to attacking both parties.

encryption - Is plausible deniability actually feasible Bruce Schneier argues in his paper about TrueCrypt and DFS (Deniable File System) that there are environment cues around partitions that look like random noise that defeat plausible deniability. Whether you believe the paper's arguments is your call (I do not), but it gives yet another sight on how plausible deniability is a weak defence. A Plausibly Deniable Encryption Scheme for Personal Data

Major Advancements in Deniable Encryption Arrive in Espionage 3.6.

Plausible Deniability.

Along the way, they resolve the 16-year-old open question of deniable encryption, posed by the researcher in 1997: in deniable encryption, a sender who is forced to reveal to an adversary both the plaintext and the key can generate fake randomness that makes the ciphertext appear to be an encryption of a different plaintext. Steganographic techniques and deniable encryption algorithms have been devised to address this specific problem. Due to the sensitive nature of data stored on mobile devices, all major mobile OS manufacturers now include some type of storage encryption. Given the recent proliferation of smart phones and tablets, we examine the feasibility of deniable storage encryption for mobile devices.