DocumentCode
3055473
Title
Establishing and fixing a freshness flaw in a key-distribution and Authentication Protocol
Author
Dojen, Reiner ; Lasc, Ioana ; Coffey, Tom
Author_Institution
Dept. of Electron.&Comput. Eng., Univ. of Limerick, Limerick
fYear
2008
fDate
28-30 Aug. 2008
Firstpage
185
Lastpage
192
Abstract
The security of electronic networks and information systems is nowadays seen as a critical issue for the growth of information and communication technologies. Cryptographic protocols are used to provide security services such as confidentiality, message integrity, authentication, certified E-mail and non-repudiation. Traditionally, security protocols have been designed and verified using informal techniques. However, the absence of formal verification can lead to security errors remaining undetected. Formal verification techniques provide a systematic way of discovering protocol flaws. This paper establishes a freshness flaw in a key-distribution and authentication protocol using an automated logic-based verification engine. The performed verification reveals a freshness flaw in the protocol that allows an intruder to impersonate legitimate principals. The cause of the freshness flaw is discussed and an amended protocol is proposed. Formal verification of the amended protocol provides confidence in the correctness and effectiveness of the proposed modifications.
Keywords
cryptographic protocols; formal verification; message authentication; E-mail; authentication protocol; automated logic-based verification engine; cryptographic protocols; electronic network security; formal verification; freshness flaw; information and communication technologies; information systems; message authentication; message confidentiality; message integrity; security services; Authentication; Communication system security; Communications technology; Computer errors; Cryptographic protocols; Electronic mail; Engines; Formal verification; Information security; Information systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligent Computer Communication and Processing, 2008. ICCP 2008. 4th International Conference on
Conference_Location
Cluj-Napoca
Print_ISBN
978-1-4244-2673-7
Type
conf
DOI
10.1109/ICCP.2008.4648371
Filename
4648371
Link To Document