(Enter summary)
Abstract: When designing and implementing cryptographic protocols one must avoid a
number of possible flaws. In this paper we divide possible flaws based on the flaw
pathology and the corresponding attack method, into elementary protocol flaws,
password/key guessing flaws, stale message flaws, parallel session flaws, internal
protocol flaws, and cryptosystem flaws. We then outline and comment on different
attack construction and inference-based formal methods, protocol analysis tools,
and process... (Update)
Context of citations to this paper: More
...cryptographic protocol attacks is helpful for cryptographic protocol analysis. There are taxonomies of cryptographic protocol flaws[5, 9] and a taxonomy of replay attacks in terms of message origin and destination[25] This paper presents an attack taxonomy based on an intruder...
...has bee able to answer are: What does this protocol achieve . Does this protocol need more assumptions than another one However, in [21], Gritzalis claims that Syverson successfully shows in [22] that BAN can not be extended to prove zero knowledge protocols. However, after...
Cited by: More
BAN Logic for Zero-Knowledge Identification Protocols - Marrotte
(Correct)
Categorizing Attacks on Cryptographic Protocols Based on.. - Xu, Kedem, Gong (2000)
(Correct)
Similar documents (at the sentence level):
5.5%: Security Protocols over open networks and.. - Gritzalis.. (1999)
(Correct)
Active bibliography (related documents): More All
0.8: A Method for Examining Cryptographic Protocols - Tjaden (1997)
(Correct)
0.5: Formal Methods for the Analysis of Authentication Protocols - Rubin, Honeyman (1993)
(Correct)
0.5: Current Approaches to Authentication in Wireless and.. - Schäfer, Festag, Karl
(Correct)
System load high. Please wait...
Timeout. Please try your query later.
Similar documents based on text: More All
0.5: The Cascade Vulnerability problem: The Detection.. - Stefanos Gritzalis.. (1997)
(Correct)
0.4: Developing Secure Web-based Medical Applications - Gritzalis, Iliadis.. (1999)
(Correct)
0.4: Trusted Third Party Services for Deploying Secure Telemedical.. - Stefanos (1999)
(Correct)
Related documents from co-citation: More All
2: Using Encryption for Authentication in Large Networks of Computers (context) - Roger, Needham et al. - 1978
2: A Logic of Authentication
- Burrows, Abadi et al. - 1990
BibTeX entry: (Update)
S. Gritzalis, D. Spinellis. "Cryptographic Protocols over Open Distributed Systems: A taxonomy of Flaws and related Protocol Analysis Tools." In Proceedings of the 16th International Conference on Computer Safety, Reliability and Security, 123-137, York, UK, September 1997. http://citeseer.ist.psu.edu/gritzalis97cryptographic.html More
@inproceedings{ gritzalis97cryptographic,
author = "Stefanos Gritzalis and Diomidis Spinellis",
title = "Cryptographic Protocols over Open Distributed Systems: {A} Taxonomy of Flaws and Related Protocol Analysis Tools",
booktitle = "16th International Conference on Computer Safety, Reliability and Security: {SAFECOMP} '97",
publisher = "Springer Verlag",
address = "Berlin, Germany~/ Heidelberg, Germany~/ London, UK~/ etc.",
pages = "123--137",
year = "1997",
url = "citeseer.ist.psu.edu/gritzalis97cryptographic.html" }
Citations (may not include all citations):
450
Using Encryption for Authentication in large networks of com.. (context) - Needham, Schroeder - 1978
322
Breaking and Fixing the Needham-Schroeder Public-Key Protoco..
- Lowe - 1996
176
Timestamps in Key Distribution Protocols (context) - Denning, Sacco - 1981
150
Encrypted Key Exchange: Password-Based Protocols Secure agai..
- Bellovin, Merritt - 1992
140
Reasoning about Belief in Cryptographic Protocols
- Gong, Needham et al. - 1990
121
Three Systems for Cryptographic Protocol Analysis (context) - Kemmerer, Meadows et al. - 1994
118
The Directory - An Authentication framework (context) - CCITT - 1988
99
Modelling and verifying key-exchange protocols using CSP and..
- Roscoe - 1995
88
Protecting Poorly Chosen Secrets from Guessing Attacks
- Gong, Lomas et al. - 1993
78
On Unifying some Cryptographic Protocol Logics
- Syverson, van Oorschot - 1994
69
iKP - a family of secure electronic payment protocols
- Bellare, Garay et al. - 1995
69
Applying Formal Methods to the Analysis of a Key-Management ..
- Meadows - 1992
61
Password Security: A Case History
- Morris - 1979
60
SPX: Global Authentication Using Public Key Certificates (context) - Tardo, Alagappan - 1991
54
Integrating Security in a large distributed system (context) - Satyanarayanan - 1989
47
Protocol Failures in Cryptosystems (context) - Moore - 1988
41
A Note on the Use of Timestamps as Nonces
- Neuman, Stubblebine - 1993
41
The Use of Logic in the Analysis of Cryptographic Protocols (context) - Syverson - 1991
41
A Taxonomy of Replay Attacks
- Syverson - 1994
40
Key Distribution Protocol for Digital Mobile Communications .. (context) - Tatebayashi, Matsuzaki et al. - 1989
31
Optimal Authentication Protocols Resistant to Password Guess..
- Gong - 1995
26
Roles in Cryptographic Protocols (context) - Snekkenes - 1992
26
On Key Distribution Protocols for Repeated Authentication
- Syverson - 1993
25
CAPSL - Common Authentication Protocol Specification Languag.. (context) - Millen - 1997
23
The Interrogator Model (context) - Millen - 1995
17
MIT Laboratory for Computer Science (context) - Shamir, Rivest et al. - 1978
16
Project Athena Technical Plan (context) - Millen, Neuman et al. - 1987
14
Foiling the Cracker: A Survey (context) - Klein - 1990
14
AUTLOG-An advanced Logic of Authentication (context) - Kessler, Wedel - 1994
12
Undetectable on-line password guessing attacks
- Ding, Horster - 1995
12
Ina Jo Specification Language Reference Manual (context) - Scheid, Holtsberg - 1988
11
Using Logics to Detect Implementation-Dependent Flaws (context) - Carlsen - 1993
10
An Interface Specification Language for Automatically Analys.. (context) - Brackin - 1997
10
Security in Open Networks and Distributed Systems (context) - Janson, Molva - 1991
10
An Introduction to Contemporary Cryptology (context) - Massey - 1988
9
Cryptographic Protocol Flaws (context) - Carlsen - 1994
8
Some Remarks on Protecting Weak Keys and PoorlyChosen Secret..
- Tsudik, Van Herreweghen - 1993
7
Authentication Protocols for Computer Networks (context) - Sidhu - 1986
7
Verification of Network Security Protocols (context) - Varadharajan - 1989
7
Automatic Formal Analyses of Cryptographic Protocols (context) - Brackin - 1996
7
Automatic Formal Analyses of Cryptographic Protocols (context) - Brackin - 1997
5
A Software Protection Scheme (context) - Purdy, Simmons et al. - 1982
5
An Augmentation of BAN-like Logics
- Mao - 1995
4
How to Selectively Broadcast a Secret (context) - Simmons - 1985
3
A survey of Password Mechanisms: Weaknesses and Potential Im.. (context) - Jobusch, Oldehoeft - 1989
2
belief and Semantics in the Analysis of Cryptographic Protoc.. (context) - Knowledge - 1992
2
Verification of the iKP family of secure electronic payment .. (context) - Pal - 1996
1
ACM Operating Systems Review (context) - of, Logic - 1990
1
ACM Transactions on Computer Systems (context) - Burrows, Abadi et al. - 1990
1
BAN logic for the analysis and verification of authenticatio.. (context) - Gritzalis - 1996
1
IEEE Transactions on Information Theory 1976; Vol (context) - Diffie, Hellman - 1976
1
Attacks in Cryptographic Protocols (context) - Gong - 1990
1
HOL Extension of GNY for Automatically Analysing Cryptograph.. (context) - Brackin - 1996
1
IEEE Transactions on Information Theory (context) - Dolev, Yao - 1983
1
ACM Operating Systems Review (context) - Otway, Rees - 1987
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC