Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use Signatures
Dennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf Sasse
摘要
The standard definition of security for digital signatures-existential unforgeability-does not ensure certain properties that protocol designers might expect. For example, in many modern signature schemes, one signature may verify against multiple different public keys. It is left to protocol designers to ensure that these properties do not break protocol security goals, often without success. Modern automated protocol analysis tools are able to prove the absence of large classes of attacks on complex real-world protocols such as TLS 1.3 and 5G. However, their abstraction of signatures assumes much more than existential unforgeability, thereby missing several classes of practical attacks. We give a hierarchy of new symbolic models for signature schemes that captures these subtleties, and thereby allows us to analyse (often unexpected) behaviours of real-world protocols that were previously out of reach of symbolic analysis. We implement our models in the Tamarin Prover, yielding the first way to perform these analyses automatically, and validate them on several case studies. In the process, we find new attacks on DRKey and SOAP's WS-Security, both protocols which were previously proven secure in traditional symbolic models.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- The Provable Security of Ed25519: Theory and PracticeJacqueline Brendel, Cas Cremers, Dennis Jackson, Mang ZhaoS&P 2021 · 被引用 78 次
- BUFFing signature schemes beyond unforgeability and the case of post-quantum signaturesCas Cremers, Samed Düzlü, Rune Fiedler, Marc Fischlin 等S&P 2021 · 被引用 37 次
- On the (In)Security of the BUFF TransformJelle Don, Serge Fehr, Yu-Hsuan Huang, Patrick StruckCRYPTO 2024 · 被引用 14 次
- An In-Depth Symbolic Security Analysis of the ACME StandardKarthikeyan Bhargavan, Abhishek Bichhawat, Quoc Huy Do, Pedram Hosseyni 等CCS 2021 · 被引用 12 次
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 被引用 11 次
它引用的顶会 Paper7
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott 等CCS 2017 · 被引用 247 次
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 被引用 233 次
- Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session ConfusionCas Cremers, Martin Dehnel-WildNDSS 2019 · 被引用 131 次
- Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed AuthenticationCas Cremers, Marko Horvat, Sam Scott, Thyla van der MerweS&P 2016 · 被引用 128 次
相关 Paper
- An Extended Hierarchy of Security Notions for Threshold Signature Schemes and Automated Analysis of Protocols That Use ThemCas Cremers, Aleksi Peltonen, Mang ZhaoCCS 2026 · 被引用 4 次
- LLM-Aided Automatic Modeling for Security Protocol VerificationZiyu Mao, Jingyi Wang, Jun Sun, Shengchao Qin 等ICSE 2025 · 被引用 3 次
- Automated Analysis of Protocols that use Authenticated Encryption: How Subtle AEAD Differences can impact Protocol SecurityCas Cremers, Alexander Dax, Charlie Jacomme, Mang ZhaoUSENIX Security 2023
- SAPIC+: protocol verifiers of the world, unite!Vincent Cheval, Charlie Jacomme, Steve Kremer, Robert KünnemannUSENIX Security 2022
- Hash Gone Bad: Automated discovery of protocol attacks that exploit hash function weaknessesVincent Cheval, Cas Cremers, Alexander Dax, Lucca Hirschi 等USENIX Security 2023
