Analysis of the IBM CCA Security API Protocols in Maude-NPA

Standards for cryptographic protocols have long been attractive candidates for formal verification. It is important that such standards be correct, and cryptographic protocols are tricky to design and subject to non-intuitive attacks even when the underlying cryptosystems are secure. Thus a number o...

Descripción completa

Detalles Bibliográficos
Autores: González Burgueño, Antonio, Santiago Pinazo, Sonia, Meadows, Catherine, Meseguer, Jose, Escobar Román, Santiago|||0000-0002-3550-4781
Tipo de recurso: capítulo de libro
Fecha de publicación:2014
País:España
Institución:Universitat Politècnica de València (UPV)
Repositorio:RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia
Idioma:inglés
OAI Identifier:oai:riunet.upv.es:10251/65130
Acceso en línea:https://riunet.upv.es/handle/10251/65130
Access Level:acceso abierto
Palabra clave:IBM 4758 common cryptographic architecture
Security Application Programming Interfaces (security APIs)
Symbolic cryptographic protocol analysis
Automatic reasoning modulo XOR theory
LENGUAJES Y SISTEMAS INFORMATICOS
id ES_c7ed4d4b339ce2c187889d01f286d07f
oai_identifier_str oai:riunet.upv.es:10251/65130
network_acronym_str ES
network_name_str España
repository_id_str
spelling Analysis of the IBM CCA Security API Protocols in Maude-NPAGonzález Burgueño, AntonioSantiago Pinazo, SoniaMeadows, CatherineMeseguer, JoseEscobar Román, Santiago|||0000-0002-3550-4781IBM 4758 common cryptographic architectureSecurity Application Programming Interfaces (security APIs)Symbolic cryptographic protocol analysisAutomatic reasoning modulo XOR theoryLENGUAJES Y SISTEMAS INFORMATICOSStandards for cryptographic protocols have long been attractive candidates for formal verification. It is important that such standards be correct, and cryptographic protocols are tricky to design and subject to non-intuitive attacks even when the underlying cryptosystems are secure. Thus a number of general-purpose cryptographic protocol analysis tools have been developed and applied to protocol standards. However, there is one class of standards, security application programming interfaces (security APIs), to which few of these tools have been applied. Instead, most work has concentrated on developing special-purpose tools and algorithms for specific classes of security APIs. However, there can be much advantage gained from having general-purpose tools that could be applied to a wide class of problems, including security APIs. One particular class of APIs that has proven difficult to analyze using general-purpose tools is that involving exclusive-or. In this paper we analyze the IBM 4758 Common Cryptographic Architecture (CCA) protocol using an advanced automated protocol verification tool with full exclusive-or capabilities, the Maude-NPA tool. This is the first time that API protocols have been satisfactorily specified and analyzed in the Maude-NPA, and the first time XOR-based APIs have been specified and analyzed using a general-purpose unbounded session cryptographic protocol verification tool that provides direct support for AC theories. We describe our results and indicate what further research needs to be done to make such protocol analysis generally effective.Antonio González-Burgueño, Sonia Santiago and Santiago Escobar have been partially supported by the EU (FEDER) and the Spanish MINECO under grants TIN 2010-21062-C02-02 and TIN 2013-45732-C4-1-P, and by Generalitat Valenciana PROMETEO2011/052. José Meseguer has been partially supported by NSF Grant CNS 13-10109.Springer International PublishingSpringer Lecture Notes in Computer Science, Vol. 8893Departamento de Sistemas Informáticos y ComputaciónEscuela Técnica Superior de Ingeniería InformáticaInstituto Universitario Valenciano de Investigación en Inteligencia ArtificialEuropean Regional Development FundMinisterio de Economía y CompetitividadGeneralitat ValencianaNational Science Foundation, EEUUMinisterio de Ciencia e InnovaciónRepositorio Institucional de la Universitat Politècnica de València Riunet20142014-01-01book parthttp://purl.org/coar/resource_type/c_3248info:eu-repo/semantics/bookPartapplication/pdfapplication/pdfhttps://riunet.upv.es/handle/10251/65130reponame:RiuNet. Repositorio Institucional de la Universitat Politécnica de Valénciainstname:Universitat Politècnica de València (UPV)InglésengMinisterio de Ciencia e Innovación http://dx.doi.org/10.13039/501100004837 TIN2010-21062-C02-02 SWEETLOGICS-UPVNational Science Foundation, China https://doi.org/10.13039/100000001 1319109 TWC: Small: Collaborative: Extensible Symbolic Analysis Modulo SMT: Combining the Powers of Rewriting, Narrowing, and SMT Solving in MaudeMinisterio de Economía y Competitividad http://dx.doi.org/10.13039/501100003329 TIN2013-45732-C4-1-P UNA APROXIMACION DECLARATIVA AL MODELADO, ANALISIS Y RESOLUCION DE PROBLEMASGeneralitat Valenciana https://doi.org/10.13039/501100003359 PROMETEO%2F2011%2F052 LOGICEXTREME: TECNOLOGIA LOGICA Y SOFTWARE SEGUROopen accesshttp://purl.org/coar/access_right/c_abf2Reserva de todos los derechoshttp://rightsstatements.org/vocab/InC/1.0/info:eu-repo/semantics/openAccessoai:riunet.upv.es:10251/651302026-06-13T07:49:27Z
dc.title.none.fl_str_mv Analysis of the IBM CCA Security API Protocols in Maude-NPA
title Analysis of the IBM CCA Security API Protocols in Maude-NPA
spellingShingle Analysis of the IBM CCA Security API Protocols in Maude-NPA
González Burgueño, Antonio
IBM 4758 common cryptographic architecture
Security Application Programming Interfaces (security APIs)
Symbolic cryptographic protocol analysis
Automatic reasoning modulo XOR theory
LENGUAJES Y SISTEMAS INFORMATICOS
title_short Analysis of the IBM CCA Security API Protocols in Maude-NPA
title_full Analysis of the IBM CCA Security API Protocols in Maude-NPA
title_fullStr Analysis of the IBM CCA Security API Protocols in Maude-NPA
title_full_unstemmed Analysis of the IBM CCA Security API Protocols in Maude-NPA
title_sort Analysis of the IBM CCA Security API Protocols in Maude-NPA
dc.creator.none.fl_str_mv González Burgueño, Antonio
Santiago Pinazo, Sonia
Meadows, Catherine
Meseguer, Jose
Escobar Román, Santiago|||0000-0002-3550-4781
author González Burgueño, Antonio
author_facet González Burgueño, Antonio
Santiago Pinazo, Sonia
Meadows, Catherine
Meseguer, Jose
Escobar Román, Santiago|||0000-0002-3550-4781
author_role author
author2 Santiago Pinazo, Sonia
Meadows, Catherine
Meseguer, Jose
Escobar Román, Santiago|||0000-0002-3550-4781
author2_role author
author
author
author
dc.contributor.none.fl_str_mv Springer Lecture Notes in Computer Science, Vol. 8893
Departamento de Sistemas Informáticos y Computación
Escuela Técnica Superior de Ingeniería Informática
Instituto Universitario Valenciano de Investigación en Inteligencia Artificial
European Regional Development Fund
Ministerio de Economía y Competitividad
Generalitat Valenciana
National Science Foundation, EEUU
Ministerio de Ciencia e Innovación
Repositorio Institucional de la Universitat Politècnica de València Riunet
dc.subject.none.fl_str_mv IBM 4758 common cryptographic architecture
Security Application Programming Interfaces (security APIs)
Symbolic cryptographic protocol analysis
Automatic reasoning modulo XOR theory
LENGUAJES Y SISTEMAS INFORMATICOS
topic IBM 4758 common cryptographic architecture
Security Application Programming Interfaces (security APIs)
Symbolic cryptographic protocol analysis
Automatic reasoning modulo XOR theory
LENGUAJES Y SISTEMAS INFORMATICOS
description Standards for cryptographic protocols have long been attractive candidates for formal verification. It is important that such standards be correct, and cryptographic protocols are tricky to design and subject to non-intuitive attacks even when the underlying cryptosystems are secure. Thus a number of general-purpose cryptographic protocol analysis tools have been developed and applied to protocol standards. However, there is one class of standards, security application programming interfaces (security APIs), to which few of these tools have been applied. Instead, most work has concentrated on developing special-purpose tools and algorithms for specific classes of security APIs. However, there can be much advantage gained from having general-purpose tools that could be applied to a wide class of problems, including security APIs. One particular class of APIs that has proven difficult to analyze using general-purpose tools is that involving exclusive-or. In this paper we analyze the IBM 4758 Common Cryptographic Architecture (CCA) protocol using an advanced automated protocol verification tool with full exclusive-or capabilities, the Maude-NPA tool. This is the first time that API protocols have been satisfactorily specified and analyzed in the Maude-NPA, and the first time XOR-based APIs have been specified and analyzed using a general-purpose unbounded session cryptographic protocol verification tool that provides direct support for AC theories. We describe our results and indicate what further research needs to be done to make such protocol analysis generally effective.
publishDate 2014
dc.date.none.fl_str_mv 2014
2014-01-01
dc.type.none.fl_str_mv book part
http://purl.org/coar/resource_type/c_3248
dc.type.openaire.fl_str_mv info:eu-repo/semantics/bookPart
format bookPart
dc.identifier.none.fl_str_mv https://riunet.upv.es/handle/10251/65130
url https://riunet.upv.es/handle/10251/65130
dc.language.none.fl_str_mv Inglés
eng
language_invalid_str_mv Inglés
language eng
dc.relation.none.fl_str_mv Ministerio de Ciencia e Innovación http://dx.doi.org/10.13039/501100004837 TIN2010-21062-C02-02 SWEETLOGICS-UPV
National Science Foundation, China https://doi.org/10.13039/100000001 1319109 TWC: Small: Collaborative: Extensible Symbolic Analysis Modulo SMT: Combining the Powers of Rewriting, Narrowing, and SMT Solving in Maude
Ministerio de Economía y Competitividad http://dx.doi.org/10.13039/501100003329 TIN2013-45732-C4-1-P UNA APROXIMACION DECLARATIVA AL MODELADO, ANALISIS Y RESOLUCION DE PROBLEMAS
Generalitat Valenciana https://doi.org/10.13039/501100003359 PROMETEO%2F2011%2F052 LOGICEXTREME: TECNOLOGIA LOGICA Y SOFTWARE SEGURO
dc.rights.none.fl_str_mv open access
http://purl.org/coar/access_right/c_abf2
Reserva de todos los derechos
http://rightsstatements.org/vocab/InC/1.0/
dc.rights.openaire.fl_str_mv info:eu-repo/semantics/openAccess
rights_invalid_str_mv open access
http://purl.org/coar/access_right/c_abf2
Reserva de todos los derechos
http://rightsstatements.org/vocab/InC/1.0/
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
application/pdf
dc.publisher.none.fl_str_mv Springer International Publishing
publisher.none.fl_str_mv Springer International Publishing
dc.source.none.fl_str_mv reponame:RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia
instname:Universitat Politècnica de València (UPV)
instname_str Universitat Politècnica de València (UPV)
reponame_str RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia
collection RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869419220712816640
score 15,301603