首页> 外文会议>International Workshop on Formal Aspects in Security and Trust >Bounded Memory Dolev-Yao Adversaries in Collaborative Systems
【24h】

Bounded Memory Dolev-Yao Adversaries in Collaborative Systems

机译:合作系统中有界内存Dolev-Yao对手

获取原文

摘要

This paper extends existing models for collaborative systems. We investigate how much damage can be done by insiders alone, without collusion with an outside adversary. In contrast to traditional intruder models, such as in protocol security, all the players inside our system, including potential adversaries, have similar capabilities. They have bounded storage capacity, that is, they can only remember at any moment a bounded number of facts. This is technically imposed by only allowing balanced actions, that is, actions that have the same number of facts in their pre and post conditions. On the other hand, the adversaries inside our system have many capabilities of the standard Dolev-Yao intruder, namely, they are able, within their bounded storage capacity, to compose, decompose, overhear, and intercept messages as well as update values with fresh ones. We investigate the complexity of the decision problem of whether or not an adversary is able to discover secret data. We show that this problem is PSPACE-complete when all actions are balanced and can update values with fresh ones. As an application we turn to security protocol analysis and demonstrate that many protocol anomalies, such as the Lowe anomaly in the Needham-Schroeder public key exchange protocol, can also occur when the intruder is one of the insiders with bounded memory.
机译:本文扩展了合作系统的现有模型。我们调查了单独的内部人可以造成多少伤害,而不会与外部对手勾结。与传统的入侵者模型相比,例如协议安全性,我们系统内的所有玩家,包括潜在的对手,具有相似的能力。它们具有界限存储容量,即,他们只能记住任何时刻的事实。这是通过仅允许平衡的行动,即在其前后条件下具有相同数量的事实的行动来实现这一点。另一方面,我们系统内的对手具有标准Dolev-yao入侵者的许多能力,即它们能够在其有界存储容量中进行编写,分解,忽略和拦截消息以及新鲜的更新值那些。我们调查反对派是否能够发现秘密数据的决策问题的复杂性。我们展示此问题是PSPACE - 完成所有操作的均衡,可以使用新鲜的操作更新值。作为应用程序,我们转向安全协议分析,并证明许多协议异常,例如Creferham-Schroeder公钥交换协议中的Lowe异常,也可能发生,当入侵者是有界存储器的一个内部人员之一时,也可能发生。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号