首页> 外文会议>International workshop on security >Verification of LINE Encryption Version 1.0 Using ProVerif
【24h】

Verification of LINE Encryption Version 1.0 Using ProVerif

机译:使用ProVerif验证LINE加密版本1.0

获取原文

摘要

LINE is currently the most popular messaging service in Japan. Communications using LINE are protected by the original encryption scheme, called LINE Encryption, and specifications of the client-to-server transport encryption protocol and the client-to-client message end-to-end encryption protocol are published by the Technical Whitepaper. Though a spoofing attack (i.e., a malicious client makes another client misunderstand the identity of the peer) and a reply attack (i.e., a message in a session is sent again in another session by a man-in-the-middle adversary, and the receiver accepts these messages) to the end-to-end protocol have been shown, no formal security analysis of these protocols is known. In this paper, we show a formal verification result of secrecy of application data and authenticity for protocols of LINE Encryption (Version 1.0) by using the automated security verification tool ProVerif. Especially, since it is claimed that the transport protocol satisfies forward secrecy (i.e., even if the static private key is leaked, security of application data is guaranteed), we verify forward secrecy for client's data and for server's data of the transport protocol, and we find an attack to break secrecy of client's application data. Moreover, we find the spoofing attack and the reply attack, which are reported in previous papers.
机译:线是目前日本最受欢迎的消息服务。使用线路的通信由原始加密方案保护,称为线路加密,以及客户到服务器传输加密协议的规范,并且由技术白皮书发布客户端到客户端消息端到端加密协议。虽然欺骗攻击(即,恶意客户端使另一个客户误解了同行的身份)和回复攻击(即,在一个中间的对手中再次在另一个会话中再次发送会话中的消息。接收器接受这些消息)已经显示到端到端协议,没有已知这些协议的正式安全分析。在本文中,我们通过使用自动安全验证工具纤维序列,显示了应用程序数据和真实性保密的正式验证结果,以及线路加密协议(版本1.0)。特别是,由于据称传输协议满足前向保密(即,即使静态私钥泄露,应用数据的安全性也是保证的),我们验证了客户端的数据和服务器的传输协议数据的保密性,以及我们发现攻击攻击客户端的应用程序数据的保密。此外,我们发现欺骗攻击和回复攻击,这些攻击是在之前的论文中报告的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号