arrow
返回

Runtime verification of cryptographic protocols

delete2010-05-01
delete13
PRE
AI
A
Andreas Bauer
J
Jan Jürjens *
DOI:10.1016/j.cose.2009.09.003delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
There has been a significant amount of work devoted to the static verification of security protocol designs Virtually all of these results, when applied to an actual implementation of a security protocol, rely on certain implicit assumptions on the implementation (for example, that the cryptographic checks that according to the design have to be performed by the protocol participants are carried out correctly) So far there seems to be no approach that would enforce these implicit assumptions for a given implementation of a security protocol (in particular regarding legacy implementations which have not been developed with formal verification in mind) In this paper, we use a code assurance technique called runtime verification to solve this open problem Runtime verification determines whether or not the behaviour observed during the execution of a system matches a given formal specification of a reference behaviour. By applying runtime verification to an implementation of any of the participants of a security protocol, we can make sure during the execution of that implementation that the implicit assumptions that had to be made to ensure the security of the overall protocol will be fulfilled The overall assurance process then proceeds in two steps First, a design model of the security protocol in UML is verified against security properties such as secrecy of data Second, the implicit assumptions on the protocol participants are derived from the design model, formalised in linear-time temporal logic, and the validity of these formulae at runtime is monitored using runtime verification The aim is to increase one's confidence that statically verified properties are satisfied not only by a model of the system, but also by the actual running system Itself We demonstrate the approach at the hand of the open source implementation Jessie of the de-facto Internet security protocol standard SSL We also briefly explain how to transfer the results to the SSL-implementation within the Java Secure Sockets Extension (JSSE) recently made open source by Sun Microsystems. (C) 2009 Elsevier Ltd All rights reserved
Keyword:
Security protocols
SSL
Java
Temporal logic
Static verification
Runtime verification
Security automata
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

D
dortmund university of technology
学者数:
9.4K
论文数: 9.1K
被引数: 15
引用论文

引用论文

Tri-axial accelerometers quantify behaviour in the Eurasian badger (Meles meles): towards an automated interpretation of field data
err2014-03-28
err0
errOAAI
errDavid W McClune; Nikki J Marks; Rory P Wilson; Jonathan DR Houghton; Ian W Montgomery; Natasha E McGowan; Eamonn Gormley; Michael Scantlebury
err分享
err收藏
1125 KUMA062 EFFECTIVELY DIGESTS GLUTEN IN THE HUMAN STOMACH: RESULTS OF A PHASE 1 STUDY
err2020-05-01
err0
PREAI
errIngrid S. Pultz; Daniel Leffler; Tina Liu; Peter Winkle; Joanne Vitanza; Malcolm Hill
err分享
err收藏
学者 查看更多内容