作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (12): 126-128. doi: 10.3969/j.issn.1000-3428.2008.12.044

• 安全技术 • 上一篇    下一篇

基于消息匹配的认证协议分析

陈力琼1,陈克非1,2   

  1. (1. 上海交通大学计算机科学与工程系,上海 200240;2. 现代通信国家重点实验室,成都 610041)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-06-20 发布日期:2008-06-20

Analysis of Authentication Protocols Based on Message Matching

CHEN Li-qiong1, CHEN Ke-fei1,2   

  1. (1. Department of Computer Science and Engineering, Shanghai Jiaotong University, Shanghai 200240;2. National Laboratory of Modern Communications, Chengdu 610041)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-06-20 Published:2008-06-20

摘要: 为了有效地分析和验证认证协议的安全性,找出协议的漏洞,介绍一种基于消息匹配的形式化分析方法。利用串空间对协议进行建模,吸取模型检测的思想,分析攻击者可能扮演的角色以及协议的执行规则,在此基础上逐步给消息和主体知识集中的变量进行赋值,并匹配消息中已被确定的常量,以此找出具体的攻击路径。同时,结合认证测试方法简化分析步骤,针对分析过程对协议进行有效的改进。

关键词: 消息匹配, 串空间, 知识集, 认证测试

Abstract: In order to analyze the authentication protocols and find attacks effectively, a formal method based on message matching is introduced. It uses strand spaces to model the protocols and analyzes possible roles the attackers can act. Based on the rules of protocols, this method assigns variants and matches constants in message and knowledge set step by step. It can utilize authentication test to reduce the scope of analysis and find the attack traces as a result. In addition, this method provides the guidance to modify the authentication protocols.

Key words: message matching, strand spaces, knowledge set, authentication test

中图分类号: