摘要
协议的分析验证方法有形式化与非形式化之分 ,很多代表性的协议虽然存在着缺陷 ,但对这些协议的非形式化分析 ,却可以提出一些值得借鉴的规则 ,参考这些规则可以避免和减少协议逻辑的漏洞 ,本文针对 Woo- L am两个改进协议以及 SSL协议给出了攻击方法 。
The methods of analyzing and verifying cryptographic protocols can be categorized into formal and informal ones. Although there are flaws in some typical protocols, we can draw a few helpful principles by informally analyzing them. Based upon those principles, cryptographic protocols are less prone to designed errors. In this paper, some new attacks upon three authentication protocols are presented. Then the reasons resulting these attacks are analyzed, and some proposals to improve the related authentication protocols are given.
出处
《小型微型计算机系统》
CSCD
北大核心
2003年第11期1912-1915,共4页
Journal of Chinese Computer Systems
基金
国家自然科学基金项目 ( 60 172 0 17)资助
关键词
认证协议
协议攻击
密码协议
密码学
非形式化方法
authentication protocol
protocol attack
cryptographic protocol
cryptography
informal method