Ceremony Design and Analysis

Ceremony Design and Analysis
复制标题

仪式设计与分析

DOI:
--
复制
发表时间:
2007
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
C. Ellison
C. Ellison
中科院分区:
--
文献类型:
--
作者:
C. Ellison

文献摘要

被引文献

相似文献

仪式的概念被引入为网络协议概念的扩展,将人类节点与计算机节点并列,并具有通信链路,包括用户界面、人与人之间的通信以及携带数据的物理对象的传输。协议的带外是仪式的带内,因此要使用用于协议设计和分析的相同成熟技术的变体进行设计和分析。仪式包括所有协议,以及具有用户界面的所有应用程序、所有工作流程和所有配置方案。一个安全的仪式是安全的,既不受正常攻击,也不受社会工程的攻击。然而,一些安全协议意味着无法确保安全的仪式。
The concept of ceremony is introduced as an extension of the concept of network protocol, with human nodes alongside computer nodes and with communication links that include UI, human-to-human communication and transfers of physical objects that carry data. What is out-of-band to a protocol is in-band to a ceremony, and therefore subject to design and analysis using variants of the same mature techniques used for the design and analysis of protocols. Ceremonies include all protocols, as well as all applications with a user interface, all workflow and all provisioning scenarios. A secure ceremony is secure against both normal attacks and social engineering. However, some secure protocols imply ceremonies that cannot be made secure.