Automated verification of equivalence properties of cryptographic protocols

Abstract : Indistinguishability properties are essential in formal verification of cryptographic protocols. They are needed to model anonymity properties, strong versions of confidentiality and resistance against offline guessing attacks. Indistinguishability properties can be conveniently modeled as equivalence properties. We present a novel procedure to verify equivalence properties for a bounded number of sessions of cryptographic protocols. As in the applied pi-calculus, our protocol specification language is parametrized by a first-order sorted term signature and an equational theory which allows formalization of algebraic properties of cryptographic primitives. Our procedure is able to verify trace equivalence for determinate cryptographic protocols. On determinate protocols, trace equivalence coincides with observational equivalence which can therefore be automatically verified for such processes. When protocols are not determinate our procedure can be used for both under- and over-approximations of trace equivalence, which proved successful on examples. The procedure can handle a large set of cryptographic primitives, namely those whose equational theory is generated by an optimally reducing convergent rewrite system. The procedure is based on a fully abstract modelling of the traces of a bounded number of sessions of the protocols into first-order Horn clauses on which a dedicated resolution procedure is used to decide equivalence properties. We have shown that our procedure terminates for the class of subterm convergent equational theories. Moreover, the procedure has been implemented in a prototype tool A-KiSs (Active Knowledge in Security Protocols) and has been effectively tested on examples. Some of the examples were outside the scope of existing tools, including checking anonymity of an electronic voting protocol due to Okamoto.
Type de document :
Article dans une revue
ACM Transactions on Computational Logic, Association for Computing Machinery, 2016, 17 (4), 〈10.1145/2926715〉
Liste complète des métadonnées

Littérature citée [56 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01306561
Contributeur : Steve Kremer <>
Soumis le : mardi 17 mai 2016 - 14:26:22
Dernière modification le : mardi 13 mars 2018 - 14:24:05
Document(s) archivé(s) le : vendredi 19 août 2016 - 16:50:53

Fichier

equivalence.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

Collections

Citation

Rohit Chadha, Vincent Cheval, Ştefan Ciobâcǎ, Steve Kremer. Automated verification of equivalence properties of cryptographic protocols. ACM Transactions on Computational Logic, Association for Computing Machinery, 2016, 17 (4), 〈10.1145/2926715〉. 〈hal-01306561〉

Partager

Métriques

Consultations de la notice

373

Téléchargements de fichiers

284