首页> 外文期刊>Security and Communications Networks >Typing secure implementation of authentication protocols in environments with compromised principals
【24h】

Typing secure implementation of authentication protocols in environments with compromised principals

机译:在主体受损的环境中键入身份验证协议的安全实现

获取原文
获取原文并翻译 | 示例

摘要

Analyzing the executable code, instead of the high-level model, of security protocols has received attention in recent years. To this end, a number of security type systems have already been proposed. These type systems are sound but incomplete. That is, a well-typed protocol is certainly secure, whereas no judgment can be made about the protocol whose type-annotated code is ill typed. In fact, the type-based analysis of a protocol would have no result unless we are able to find a well-typed code that represents both the protocol and the attacker's capabilities. As there is a very large space of possible type annotations and adversary models, this requires a profound knowledge of the rationale behind the underlying type system as well as the components of the protocol being analyzed. The problem is aggravated when the protocol runs in environments containing compromised principals. These issues have rendered the use of such type systems somewhat impractical. This paper is an attempt to resolve the problem for authentication protocols in environments containing Dolev-Yao attackers. We concretize our ideas in F5, a security type checker, and suggest effective type annotations and so-called attacker interfaces representing the capabilities of a general adversary. Copyright (c) 2013 John Wiley & Sons, Ltd.
机译:近年来,分析安全协议的可执行代码而不是高级模型已引起关注。为此,已经提出了许多安全类型系统。这些类型的系统健全但不完整。也就是说,类型正确的协议当然是安全的,而无法判断类型标注代码类型错误的协议。实际上,除非我们能够找到代表该协议和攻击者功能的良好类型的代码,否则对协议进行基于类型的分析将不会有结果。由于存在大量可能的类型注释和对手模型的空间,因此这需要对底层类型系统以及所分析协议的组成部分背后的原理有深入的了解。当协议在包含受损主体的环境中运行时,该问题会更加严重。这些问题使得使用这种类型的系统有些不切实际。本文旨在解决包含Dolev-Yao攻击者的环境中的身份验证协议问题。我们在安全性类型检查器F5中具体化我们的想法,并建议有效的类型注释和代表一般对手能力的所谓攻击者接口。版权所有(c)2013 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号