从Woo-Lam协议到网络协议的抽象验证
ABSTRACT VERIFICATION OF NETWORK PROTOCOLS
-
摘要: 形式化方法是验证加密协议的重要手段 ,提出了一种新的验证方法 ,该方法基于 Debbabi的推理规则 ,将参与者 ID|参与者密钥等数据结构从协议中抽象出来 ,建立起抽象的逻辑推理结构 .以 Woo- L am协议为例 ,通过逆向递推的方式得到了协议的所有攻击路径 ,并以图的形式表示其关系 ,详尽分析了协议的漏洞 ,最后 ,提出了如何使协议更为安全的建议Abstract: Formal method is an important way of verifying cryptographic protocols. Based on the deduction rules of Debbabi, a new approach is presented, which abstracts some data structures, such as principals’ids and keys, from the protocol, and then builds up the architecture of reasoning logic. By adverse deduction, all paths of attacks on Woo Lam protocol can be obained in terms of chart and all the flaws of the protocol can be analyzed thoroughly. Finally, suggestions about making the protocol more secure are given.
下载: