Roles in cryptographic protocols
Einar Snekkenes
Abstract
Einar Snekkenes
Abstract
In protocols for the distribution of symmetric keys, a principal will usually either take on the role as a session key provider or as a session key user. A principal taking on the role as session key user may also act as the master or the slave. Methods for the analysis of cryptographic protocols that fail to properly handle multiple roles are demonstrated to yield undependable results. A protocol, KP, similar to the Needham and Schroeder symmetric key distribution protocol (1978) is presented. An example is provided to show how a multirole flaw in KP can be utilized by an adversary to obtain a session key. Using a method due to M. Burrows et al. (1989) and P. Bieber (1990) it is shown that KP seems to be suitable for secure key distribution. The approach due to P. Bieber is then modified to facilitate the detection of the class of multirole flaws.>
OpenAlex reports 43 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In protocols for the distribution of symmetric keys, a principal will usually either take on the role as a session key provider or as a session key user. A principal taking on the role as session key user may also act as the master or the slave. Methods for the analysis of cryptographic protocols that fail to properly handle multiple roles are demonstrated to yield undependable results. A protocol, KP, similar to the Needham and Schroeder symmetric key distribution protocol (1978) is presented. An example is provided to show how a multirole flaw in KP can be utilized by an adversary to obtain a session key. Using a method due to M. Burrows et al. (1989) and P. Bieber (1990) it is shown that KP seems to be suitable for secure key distribution. The approach due to P. Bieber is then modified to facilitate the detection of the class of multirole flaws.>
Key concepts: Session (web analytics), Computer science, Key (lock), Principal (computer security), Cryptography, Key distribution, Protocol (science), Session key