...
首页> 外文期刊>International Journal of Information Security >Measuring protocol strength with security goals
【24h】

Measuring protocol strength with security goals

机译:通过安全目标衡量协议强度

获取原文
获取原文并翻译 | 示例

摘要

Flaws in published standards for security protocols are found regularly, often after systems implementing those standards have been deployed. Because of deployment constraints and disagreements among stakeholders, different fixes may be proposed and debated. In this process, security improvements must be balanced with issues of functionality and compatibility. This paper provides a family of rigorous metrics for protocol security improvements. These metrics are sets of first-order formulas in a goal language associated with a protocol . The semantics of is compatible with many ways to analyze protocols, and some metrics in this family are supported by many protocol analysis tools. Other metrics are supported by our Cryptographic Protocol Shapes Analyzer cpsa. This family of metrics refines several "hierarchies" of security goals in the literature. Our metrics are applicable even when, to mitigate a flaw, participants must enforce policies that constrain protocol execution. We recommend that protocols submitted to standards groups characterize their goals using formulas in , and that discussions comparing alternative protocol refinements measure their security in these terms.
机译:经常在部署实现这些标准的系统之后,定期发现已发布的安全协议标准中的缺陷。由于部署限制和利益相关者之间的分歧,可能会提出并讨论不同的解决方案。在此过程中,必须在功能和兼容性问题之间平衡安全性改进。本文为协议安全性改进提供了一系列严格的指标。这些度量是与协议关联的目标语言中的一阶公式集。的语义与分析协议的许多方式兼容,并且该家族中的某些度量标准得到许多协议分析工具的支持。我们的加密协议形状分析器cpsa支持其他指标。该系列指标改进了文献中的安全目标的多个“层次结构”。即使为了减轻漏洞,参与者必须执行限制协议执行的策略,我们的指标仍然适用。我们建议提交给标准组的协议使用中的公式来描述其目标,并建议比较替代协议改进的讨论以此来衡量其安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号