See this document in CiteSeerX!

Cryptographic Protocols over Open Distributed Systems: A Taxonomy of Flaws and related Protocol Analysis Tools (1997)  (Make Corrections)  (2 citations)
S. Gritzalis, D. Spinellis
16th International Conference on Computer Safety, Reliability and Security: SAFECOMP '97



  Home/Search   Context   Related

 
View or download:
kerkis.math.aegean.gr/~dspin/...doc.pdf
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  kerkis.math.aegean.gr/~dspi...doc (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: When designing and implementing cryptographic protocols one must avoid a number of possible flaws. In this paper we divide possible flaws based on the flaw pathology and the corresponding attack method, into elementary protocol flaws, password/key guessing flaws, stale message flaws, parallel session flaws, internal protocol flaws, and cryptosystem flaws. We then outline and comment on different attack construction and inference-based formal methods, protocol analysis tools, and process... (Update)

Context of citations to this paper:   More

...cryptographic protocol attacks is helpful for cryptographic protocol analysis. There are taxonomies of cryptographic protocol flaws[5, 9] and a taxonomy of replay attacks in terms of message origin and destination[25] This paper presents an attack taxonomy based on an intruder...

...has bee able to answer are: What does this protocol achieve . Does this protocol need more assumptions than another one However, in [21], Gritzalis claims that Syverson successfully shows in [22] that BAN can not be extended to prove zero knowledge protocols. However, after...

Cited by:   More
BAN Logic for Zero-Knowledge Identification Protocols - Marrotte   (Correct)
Categorizing Attacks on Cryptographic Protocols Based on.. - Xu, Kedem, Gong (2000)   (Correct)

Similar documents (at the sentence level):
5.5%:   Security Protocols over open networks and.. - Gritzalis.. (1999)   (Correct)

Active bibliography (related documents):   More   All
0.8:   A Method for Examining Cryptographic Protocols - Tjaden (1997)   (Correct)
0.5:   Formal Methods for the Analysis of Authentication Protocols - Rubin, Honeyman (1993)   (Correct)
0.5:   Current Approaches to Authentication in Wireless and.. - Schäfer, Festag, Karl   (Correct)

System load high. Please wait...
Timeout. Please try your query later.
Similar documents based on text:   More   All
0.5:   The Cascade Vulnerability problem: The Detection.. - Stefanos Gritzalis.. (1997)   (Correct)
0.4:   Developing Secure Web-based Medical Applications - Gritzalis, Iliadis.. (1999)   (Correct)
0.4:   Trusted Third Party Services for Deploying Secure Telemedical.. - Stefanos (1999)   (Correct)

Related documents from co-citation:   More   All
2:   Using Encryption for Authentication in Large Networks of Computers (context) - Roger, Needham et al. - 1978
2:   A Logic of Authentication - Burrows, Abadi et al. - 1990

BibTeX entry:   (Update)

S. Gritzalis, D. Spinellis. "Cryptographic Protocols over Open Distributed Systems: A taxonomy of Flaws and related Protocol Analysis Tools." In Proceedings of the 16th International Conference on Computer Safety, Reliability and Security, 123-137, York, UK, September 1997. http://citeseer.ist.psu.edu/gritzalis97cryptographic.html   More

@inproceedings{ gritzalis97cryptographic,
    author = "Stefanos Gritzalis and Diomidis Spinellis",
    title = "Cryptographic Protocols over Open Distributed Systems: {A} Taxonomy of Flaws and Related Protocol Analysis Tools",
    booktitle = "16th International Conference on Computer Safety, Reliability and Security: {SAFECOMP} '97",
    publisher = "Springer Verlag",
    address = "Berlin, Germany~/ Heidelberg, Germany~/ London, UK~/ etc.",
    pages = "123--137",
    year = "1997",
    url = "citeseer.ist.psu.edu/gritzalis97cryptographic.html" }
Citations (may not include all citations):
450   Using Encryption for Authentication in large networks of com.. (context) - Needham, Schroeder - 1978
322   Breaking and Fixing the Needham-Schroeder Public-Key Protoco.. - Lowe - 1996
176   Timestamps in Key Distribution Protocols (context) - Denning, Sacco - 1981
150   Encrypted Key Exchange: Password-Based Protocols Secure agai.. - Bellovin, Merritt - 1992
140   Reasoning about Belief in Cryptographic Protocols - Gong, Needham et al. - 1990
121   Three Systems for Cryptographic Protocol Analysis (context) - Kemmerer, Meadows et al. - 1994
118   The Directory - An Authentication framework (context) - CCITT - 1988
99   Modelling and verifying key-exchange protocols using CSP and.. - Roscoe - 1995
88   Protecting Poorly Chosen Secrets from Guessing Attacks - Gong, Lomas et al. - 1993
78   On Unifying some Cryptographic Protocol Logics - Syverson, van Oorschot - 1994
69   iKP - a family of secure electronic payment protocols - Bellare, Garay et al. - 1995
69   Applying Formal Methods to the Analysis of a Key-Management .. - Meadows - 1992
61   Password Security: A Case History - Morris - 1979
60   SPX: Global Authentication Using Public Key Certificates (context) - Tardo, Alagappan - 1991
54   Integrating Security in a large distributed system (context) - Satyanarayanan - 1989
47   Protocol Failures in Cryptosystems (context) - Moore - 1988
41   A Note on the Use of Timestamps as Nonces - Neuman, Stubblebine - 1993
41   The Use of Logic in the Analysis of Cryptographic Protocols (context) - Syverson - 1991
41   A Taxonomy of Replay Attacks - Syverson - 1994
40   Key Distribution Protocol for Digital Mobile Communications .. (context) - Tatebayashi, Matsuzaki et al. - 1989
31   Optimal Authentication Protocols Resistant to Password Guess.. - Gong - 1995
26   Roles in Cryptographic Protocols (context) - Snekkenes - 1992
26   On Key Distribution Protocols for Repeated Authentication - Syverson - 1993
25   CAPSL - Common Authentication Protocol Specification Languag.. (context) - Millen - 1997
23   The Interrogator Model (context) - Millen - 1995
17   MIT Laboratory for Computer Science (context) - Shamir, Rivest et al. - 1978
16   Project Athena Technical Plan (context) - Millen, Neuman et al. - 1987
14   Foiling the Cracker: A Survey (context) - Klein - 1990
14   AUTLOG-An advanced Logic of Authentication (context) - Kessler, Wedel - 1994
12   Undetectable on-line password guessing attacks - Ding, Horster - 1995
12   Ina Jo Specification Language Reference Manual (context) - Scheid, Holtsberg - 1988
11   Using Logics to Detect Implementation-Dependent Flaws (context) - Carlsen - 1993
10   An Interface Specification Language for Automatically Analys.. (context) - Brackin - 1997
10   Security in Open Networks and Distributed Systems (context) - Janson, Molva - 1991
10   An Introduction to Contemporary Cryptology (context) - Massey - 1988
9   Cryptographic Protocol Flaws (context) - Carlsen - 1994
8   Some Remarks on Protecting Weak Keys and PoorlyChosen Secret.. - Tsudik, Van Herreweghen - 1993
7   Authentication Protocols for Computer Networks (context) - Sidhu - 1986
7   Verification of Network Security Protocols (context) - Varadharajan - 1989
7   Automatic Formal Analyses of Cryptographic Protocols (context) - Brackin - 1996
7   Automatic Formal Analyses of Cryptographic Protocols (context) - Brackin - 1997
5   A Software Protection Scheme (context) - Purdy, Simmons et al. - 1982
5   An Augmentation of BAN-like Logics - Mao - 1995
4   How to Selectively Broadcast a Secret (context) - Simmons - 1985
3   A survey of Password Mechanisms: Weaknesses and Potential Im.. (context) - Jobusch, Oldehoeft - 1989
2   belief and Semantics in the Analysis of Cryptographic Protoc.. (context) - Knowledge - 1992
2   Verification of the iKP family of secure electronic payment .. (context) - Pal - 1996
1   ACM Operating Systems Review (context) - of, Logic - 1990
1   ACM Transactions on Computer Systems (context) - Burrows, Abadi et al. - 1990
1   BAN logic for the analysis and verification of authenticatio.. (context) - Gritzalis - 1996
1   IEEE Transactions on Information Theory 1976; Vol (context) - Diffie, Hellman - 1976
1   Attacks in Cryptographic Protocols (context) - Gong - 1990
1   HOL Extension of GNY for Automatically Analysing Cryptograph.. (context) - Brackin - 1996
1   IEEE Transactions on Information Theory (context) - Dolev, Yao - 1983
1   ACM Operating Systems Review (context) - Otway, Rees - 1987

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC