A LOGIC OF AUTHENTICATION

A LOGIC OF AUTHENTICATION
复制标题

DOI:
10.1098/rspa.1989.0125
复制
发表时间:
1989-12-08
期刊:
PROCEEDINGS OF THE ROYAL SOCIETY OF LONDON SERIES A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES
影响因子:
--
通讯作者:
NEEDHAM, RM
NEEDHAM, RM
中科院分区:
其他
文献类型:
--
作者:
BURROWS, M;ABADI, M;NEEDHAM, RM

文献摘要

被引文献

相似文献

身份验证协议是许多分布式系统中安全性的基础,因此确保这些协议正确运行至关重要。不幸的是,他们的设计非常容易出错。文献中发现的大多数协议都包含冗余或安全缺陷。一个简单的逻辑,使我们能够描述的信任参与认证协议和这些信念的通信的结果的演变。我们已经能够正式解释各种身份验证协议,发现其中的微妙之处和错误,并提出改进建议。在本文中,我们提出的逻辑,然后给出我们的分析结果的四个已公布的协议,选择无论是因为他们的实际重要性,因为他们来说明我们的方法。
Authentication protocols are the basis of security in many distributed systems, and it is therefore essential to ensure that these protocols function correctly. Unfortunately, their design has been extremely error prone. Most of the protocols found in the literature contain redundancies or security flaws. A simple logic has allowed us to describe the beliefs of trustworthy parties involved in authentication protocols and the evolution of these beliefs as a consequence of communication. We have been able to explain a variety of authentication protocols formally, to discover subtleties and errors in them, and to suggest improvements. In this paper we present the logic and then give the results of our analysis of four published protocols, chosen either because of their practical importance or because they serve to illustrate our method.