【24h】

Formalizing and Analyzing Sender Invariance

机译:正式和分析发件人不变性

获取原文

摘要

In many network applications and services, agents that share no secure channel in advance may still wish to communicate securely with each other. In such settings, one often settles for achieving security goals weaker than authentication, such as sender invariance. Informally, sender invariance means that all messages that seem to come from the same source actually do, where the source can perhaps only be identified by a pseudonym. This implies, in particular, that the relevant parts of messages cannot be modified by an intruder. In this paper, we provide the first formal definition of sender invariance as well as a stronger security goal that we call strong sender invariance. We show that both kinds of sender invariance are closely related to, and entailed by, weak authentication, the primary difference being that sender invariance is designed for the context where agents can only be identified pseudonymously. In addition to clarifying how sender invariance and authentication are related, this result shows how a broad class of automated tools can be used for the analysis of sender invariance protocols. As a case study, we describe the analysis of two sender invariance protocols using the OFMC back-end of the AVISPA Tool.
机译:在许多网络应用程序和服务中,预先共享安全渠道的代理可能仍希望彼此安全地进行通信。在这种设置中,一个经常为实现比身份验证的安全目标稳定,例如发件人不变性。非正式地,发件人不变性意味着似乎来自同一来源的所有消息实际上都是这样做的,其中源只能由假名识别。这尤其意味着,无法通过入侵者修改消息的相关部分。在本文中,我们提供了发件人不变性的第一个正式定义,以及我们称之为强大的发件人不变性的更强大的安全目标。我们表明,两种发件人不变性与身份验证疲软的弱点密切相关,发件人不变性的主要区别是因为只能识别代理的上下文。除了澄清发件人的不变性和身份验证如何相关,此结果表明,如何使用广泛的自动化工具来分析发件人不变性协议。作为一个案例研究,我们使用Avispa工具的ofmc返回端描述了对两个发件人不变性协议的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号