Security Analysis on Mutual Authentication against Man-in-the-Middle Attack
Zhe Chen, Shize Guo, Rong Duan, Sheng Wang
Abstract
Zhe Chen, Shize Guo, Rong Duan, Sheng Wang
Abstract
Authentication is the basic security service in an open and vulnerable communications network such as the Internet. Unilateral authentication is vulnerable to the Man-in-the-Middle (MitM) attack. The security of mutual authentication against MitM attack is also weak. As case studies, we discuss the security of the well-known mutual authentication protocol-Secure Sockets Layer (SSL) protocol, examine the MitM attack to it and investigate causes. In this paper, a unified mathematical model is established to analyze Man-in-the-Middle attacks to mutual authentication protocol. Then we use the formal methods and logical operations to analyze the mutual authentication security against MitM attack. Finally, we propose a modification to the model of MitM attack that prevents such attacks.
OpenAlex reports 20 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Authentication is the basic security service in an open and vulnerable communications network such as the Internet. Unilateral authentication is vulnerable to the Man-in-the-Middle (MitM) attack. The security of mutual authentication against MitM attack is also weak. As case studies, we discuss the security of the well-known mutual authentication protocol-Secure Sockets Layer (SSL) protocol, examine the MitM attack to it and investigate causes. In this paper, a unified mathematical model is established to analyze Man-in-the-Middle attacks to mutual authentication protocol. Then we use the formal methods and logical operations to analyze the mutual authentication security against MitM attack. Finally, we propose a modification to the model of MitM attack that prevents such attacks.
Key concepts: Man-in-the-middle attack, Mutual authentication, Computer science, Computer security, Authentication protocol, Authentication (law), Challenge–response authentication, Reflection attack