首页> 外文会议>International Conference on Digital Information Management >Applying authentication tests to discover Man-In-The-Middle attack in security protocols
【24h】

Applying authentication tests to discover Man-In-The-Middle attack in security protocols

机译:应用身份验证测试以发现安全协议中的中间人攻击

获取原文

摘要

Authentication protocols ensure that participants in a distributed environment verify their identities before sending sensitive information to each other. If an authentication protocol has a design flaw, it may fail to reveal the true identities of distributed participants. To verify that an authentication protocol achieves its objectives, we have developed Authentication Tests based on Distributed Temporal Protocol Logic (DTPL). In this paper, we propose a generic strategy to analyze authentication protocols based on these Authentication Tests. We demonstrate the ease with which our proposed strategy can be used by applying these tests on famous Needham-Shroeder Public Key (NSPK) authentication protocol. We also demonstrate how the inability to prove a security property can lead us to identifying Man-In-The-Middle attack on such protocols.
机译:身份验证协议可确保分布式环境中的参与者在相互发送敏感信息之前先验证其身份。如果身份验证协议具有设计缺陷,则可能无法揭示分布式参与者的真实身份。为了验证身份验证协议是否达到其目标,我们开发了基于分布式时间协议逻辑(DTPL)的身份验证测试。在本文中,我们提出了一种基于这些认证测试来分析认证协议的通用策略。通过在著名的Needham-Shroeder公钥(NSPK)身份验证协议上应用这些测试,我们证明了我们提出的策略可以轻松使用。我们还演示了无法证明安全属性如何导致我们识别此类协议的中间人攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号