Automated Analysis of Protocols that use Authenticated Encryption: How Subtle AEAD Differences can impact Protocol Security
Cas Cremers, Alexander Dax, Charlie Jacomme, Mang Zhao
摘要
Many modern security protocols such as TLS, WPA2, Wire-Guard, and Signal use a cryptographic primitive called Authenticated Encryption (optionally with Authenticated Data), also known as an AEAD scheme. AEAD is a variant of symmetric encryption that additionally provides authentication. While authentication may seem to be a straightforward additional requirement, it has in fact turned out to be complex: many different security notions for AEADs are still being proposed, and several recent protocol-level attacks exploit subtle behaviors that differ among real-world AEAD schemes. We provide the first automated analysis method for protocols that use AEADs that can systematically find attacks that exploit the subtleties of the specific type of AEAD used. This can then be used to analyze specific protocols with a fixed AEAD choice, or to provide guidance on which AEADs might be (in)sufficient to make a protocol design secure. We develop generic symbolic AEAD models, which we instantiate for the Tamarin prover. Our approach can automatically and efficiently discover protocol attacks that could previously only be found using manual inspection, such as the Salamander attack on Facebook's message franking, and attacks on SFrame and YubiHSM. Furthermore, our analysis reveals undesirable behaviors of several other protocols. * = Feasibility depends on the collision resistance of XSalsa20-Poly1305 (not in Table 2.) See discussion in the full version [19] . ‡ = Reported to WhatsApp. Feasibility heavily relies on implementation details, which are not open source.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- An Extended Hierarchy of Security Notions for Threshold Signature Schemes and Automated Analysis of Protocols That Use ThemCas Cremers, Aleksi Peltonen, Mang ZhaoCCS 2026 · 被引用 4 次
- Untangling the Knot: Breaking Access Control in Home Wireless Mesh NetworksXin'an Zhou, Qing Deng, Juefei Pu, Keyu Man 等CCS 2024 · 被引用 2 次
- The SecureDrop Protocol: End-to-End Encrypted Whistleblowing for AllGiulio Berra, Felix Linker, Luca Maier, Cory Francis Myers 等CCS 2026
- Formal Security Analysis of the Olvid MessengerNoemi Terzo), Cas Cremers, Ruben Gonzalez, Peter Schwabe) 等CCS 2026
- A Formal Analysis of Apple's iMessage PQ3 ProtocolFelix Linker, Ralf Sasse, David A. BasinUSENIX Security 2025
它引用的顶会 Paper13
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 被引用 437 次
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott 等CCS 2017 · 被引用 247 次
- ProVerif with Lemmas, Induction, Fast Subsumption, and Much MoreBruno Blanchet, Vincent Cheval, Véronique CortierS&P 2022 · 被引用 61 次
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 被引用 57 次
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 被引用 54 次
相关 Paper
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 被引用 53 次
- Hash Gone Bad: Automated discovery of protocol attacks that exploit hash function weaknessesVincent Cheval, Cas Cremers, Alexander Dax, Lucca Hirschi 等USENIX Security 2023
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 被引用 11 次
- A comprehensive, formal and automated analysis of the EDHOC protocolCharlie Jacomme, Elise Klein, Steve Kremer, Maïwenn RacouchotUSENIX Security 2023
- Secure Protocol Composition under Dynamic Corruption: Scaling Up Symbolic Analysis for Real-World Security PropertiesCas Cremers, Erik Pallas, Aleksi PeltonenUSENIX Security 2026
