Pretražite po imenu i prezimenu autora, mentora, urednika, prevoditelja

Napredna pretraga

Pregled bibliografske jedinice broj: 1100853

Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication


Cremers, Cas; Horvat, Marko; Scott, Sam; van der Merwe, Thyla
Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication // 2016 IEEE Symposium on Security and Privacy (SP)
San Jose (CA), Sjedinjene Američke Države: Institute of Electrical and Electronics Engineers (IEEE), 2016. str. 470-485 doi:10.1109/sp.2016.35 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)


CROSBI ID: 1100853 Za ispravke kontaktirajte CROSBI podršku putem web obrasca

Naslov
Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication

Autori
Cremers, Cas ; Horvat, Marko ; Scott, Sam ; van der Merwe, Thyla

Vrsta, podvrsta i kategorija rada
Radovi u zbornicima skupova, cjeloviti rad (in extenso), znanstveni

Skup
2016 IEEE Symposium on Security and Privacy (SP)

Mjesto i datum
San Jose (CA), Sjedinjene Američke Države, 23.05.2016. - 25.05.2016

Vrsta sudjelovanja
Predavanje

Vrsta recenzije
Međunarodna recenzija

Ključne riječi
security protocols ; verification ; TLS 1.3

Sažetak
After a development process of many months, the TLS 1.3 specification is nearly complete. To prevent past mistakes, this crucial security protocol must be thoroughly scrutinised prior to deployment. In this work we model and analyse the latest draft of the TLS 1.3 specification, namely revision 10, using the Tamarin prover, a tool for the automated analysis of security protocols. We specify and analyse the interaction of various handshake modes for an unbounded number of concurrent TLS connec- tions. We show that revision 10 meets the goals of authenticated key exchange in both the unilateral and mutual authentication cases. We extend our model to incorporate the desired delayed client authentication mechanism, a feature that is likely to be included in the next revision of the specification, and uncover a potential attack in which an adversary is able to successfully impersonate a client during a PSK-resumption handshake. This observation was reported to, and confirmed by, the IETF TLS Working Group. Our work not only provides the first supporting evidence for the security of several complex protocol mode interactions in TLS 1.3, but also shows the strict necessity of recent sugges- tions to include more information in the protocol’s signature contents.

Izvorni jezik
Engleski

Znanstvena područja
Matematika, Računarstvo



POVEZANOST RADA


Ustanove:
Prirodoslovno-matematički fakultet, Matematički odjel, Zagreb,
Prirodoslovno-matematički fakultet, Zagreb

Profili:

Avatar Url Marko Horvat (autor)

Poveznice na cjeloviti tekst rada:

doi ieeexplore.ieee.org

Citiraj ovu publikaciju:

Cremers, Cas; Horvat, Marko; Scott, Sam; van der Merwe, Thyla
Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication // 2016 IEEE Symposium on Security and Privacy (SP)
San Jose (CA), Sjedinjene Američke Države: Institute of Electrical and Electronics Engineers (IEEE), 2016. str. 470-485 doi:10.1109/sp.2016.35 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)
Cremers, C., Horvat, M., Scott, S. & van der Merwe, T. (2016) Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication. U: 2016 IEEE Symposium on Security and Privacy (SP) doi:10.1109/sp.2016.35.
@article{article, author = {Cremers, Cas and Horvat, Marko and Scott, Sam and van der Merwe, Thyla}, year = {2016}, pages = {470-485}, DOI = {10.1109/sp.2016.35}, keywords = {security protocols, verification, TLS 1.3}, doi = {10.1109/sp.2016.35}, title = {Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication}, keyword = {security protocols, verification, TLS 1.3}, publisher = {Institute of Electrical and Electronics Engineers (IEEE)}, publisherplace = {San Jose (CA), Sjedinjene Ameri\v{c}ke Dr\v{z}ave} }
@article{article, author = {Cremers, Cas and Horvat, Marko and Scott, Sam and van der Merwe, Thyla}, year = {2016}, pages = {470-485}, DOI = {10.1109/sp.2016.35}, keywords = {security protocols, verification, TLS 1.3}, doi = {10.1109/sp.2016.35}, title = {Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed Authentication}, keyword = {security protocols, verification, TLS 1.3}, publisher = {Institute of Electrical and Electronics Engineers (IEEE)}, publisherplace = {San Jose (CA), Sjedinjene Ameri\v{c}ke Dr\v{z}ave} }

Časopis indeksira:


  • Web of Science Core Collection (WoSCC)
    • Conference Proceedings Citation Index - Science (CPCI-S)
  • Scopus


Citati:





    Contrast
    Increase Font
    Decrease Font
    Dyslexic Font