...
首页> 外文期刊>IEEE Journal on Selected Areas in Communications >Formal characterization and automated analysis of known-pair and chosen-text attacks
【24h】

Formal characterization and automated analysis of known-pair and chosen-text attacks

机译:形式描述和自动分析已知对和选择文本的攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Formal methods have been successfully applied to exceedingly abstract system specifications to verify high level security properties such as authentication, key exchange, and fail-safe revocation. Furthermore, considerable research exists on evaluating particular ciphers and secure hash functions used to implement high level security properties. However, verifying that less abstract system specifications satisfy low level security properties has been largely impractical. This is evidenced by innumerable system vulnerabilities where high level properties are not attained due to failed assumptions of low level properties. This paper presents ongoing work on investigating known pairs and chosen text using the NRL Protocol Analyzer. We give a formal characterization of known and chosen pairs, and translate it to necessary and sufficiency conditions in the NRL Protocol Analyzer model. It is the first work the authors are aware of automatically discovering known-pair and chosen-text attacks. We describe the use of the analyzer to rediscover attacks, to find new variants of attacks on an early version of the ESP protocol, and to show how our experience in using it has led us to refine our model. This was the first use of the Analyzer to model protocols at such a low level of abstraction.
机译:形式化方法已成功应用于极其抽象的系统规范,以验证高级安全性,例如身份验证,密钥交换和故障安全吊销。此外,在评估用于实现高级安全属性的特定密码和安全哈希函数方面,存在大量研究。但是,验证不太抽象的系统规范满足低级安全性在很大程度上是不切实际的。这由无数的系统漏洞证明,其中由于对低级别属性的假设失败而无法获得高级属性。本文介绍了使用NRL协议分析器调查已知对和选定文本的正在进行的工作。我们对已知和选定的对进行形式化表征,并将其转换为NRL协议分析器模型中的必要条件和充分条件。这是作者意识到自动发现已知对和选定文本攻击的第一项工作。我们描述了使用分析器重新发现攻击,在早期版本的ESP协议中发现新的攻击变种以及如何使用它的经验如何使我们完善模型。这是分析器首次在如此低的抽象级别上对协议建模。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号