arrow
Return

Combining model learning and formal analysis: A framework for protocol implementation verification

delete2025-06-02
delete0
PRE
AI
田凯 (Kai Tian)
C
Chunxiang Gu
F
Fushan Wei
X
Xieli Zhang
J
Jiaxing Guo
DOI:10.1016/j.jisa.2025.104079delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Ensuring the security of cryptographic protocols in practice is challenging due to the complexity of state transitions, cryptographic dependencies, and dynamic interactions. Real-world implementations often deviate from formal specifications, introducing subtle vulnerabilities that compromise key security properties such as confidentiality and authentication. To address this challenge, we propose a lightweight verification framework that integrates model learning with the Applied Pi calculus, enabling automated analysis of security protocol implementations. Our approach consists of two key components: (1) an Extended Mealy Machine (EMM) model that captures both control flow and data flow semantics to represent protocol behavior, and (2) a formal verification framework translating execution paths into symbolic models for automated analysis using ProVerif. We validated the framework on multiple TLS implementations, demonstrating its ability to uncover critical vulnerabilities such as authentication bypass and confidentiality violations. The results show that our method achieves a balance between precision and efficiency, providing a scalable and practical solution for real-world systems.

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
1.9K
Citations:
4.9K

Organization

No organization information available