• DocumentCode
    2357795
  • Title

    The rigorous implementation of a fair exchange protocol for non-repudiable Web service interactions - a case study

  • Author

    Cook, Nick ; Robinson, Paul ; Shrivastava, Santosh

  • Author_Institution
    Newcastle Univ., Newcastle
  • fYear
    2007
  • fDate
    17-20 April 2007
  • Firstpage
    307
  • Lastpage
    314
  • Abstract
    The correct implementation of security protocols is a challenging task. To achieve a high degree of confidence in an implementation, as with any software, ideally one requires both: (i) a formal specification that has been subjected to verification, and (it) tool support to generate an implementation from the verified specification. The formal specification and verification of security protocols has attracted considerable attention, with corresponding advances. However, the state of the art in the generation of implementations has not progressed beyond relatively simple protocols. This paper presents a case study on the implementation of a deterministically fair non-repudiation protocol. Such protocols are among the most complex of security protocols. Sub-protocols are typically required to guarantee timely termination. A trusted third party must be involved to guarantee fairness. Finally, to satisfy requirements such as non-repudiable audit, significant infrastructure support is needed. The case study demonstrates an improved approach to protocol implementation. Starting with a formal specification, a rigorous process with considerable tool support leads to the deployment of a protocol implementation in a flexible Web services-based execution framework. The paper concludes with an evaluation of the approach.
  • Keywords
    Web services; formal specification; protocols; security of data; fair exchange protocol; formal specification; nonrepudiable Web service interactions; nonrepudiable audit; security protocols; Authentication; Collaboration; Formal specifications; Middleware; Protocols; Security; Software tools; Web services; XML; B2B interaction; Web services; XML processing; middleware; non-repudiation; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Data Engineering Workshop, 2007 IEEE 23rd International Conference on
  • Conference_Location
    Istanbul
  • Print_ISBN
    978-1-4244-0831-3
  • Electronic_ISBN
    978-1-4244-0832-0
  • Type

    conf

  • DOI
    10.1109/ICDEW.2007.4401010
  • Filename
    4401010