Analysis of the IBM CCA Security API Protocols in Maude-NPA
Standards for cryptographic protocols have long been attractive candidates for formal verification. It is important that such standards be correct, and cryptographic protocols are tricky to design and subject to non-intuitive attacks even when the underlying cryptosystems are secure. Thus a number o...
| Autores: | , , , , |
|---|---|
| Tipo de recurso: | capítulo de libro |
| Fecha de publicación: | 2014 |
| País: | España |
| Institución: | Universitat Politècnica de València (UPV) |
| Repositorio: | RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia |
| Idioma: | inglés |
| OAI Identifier: | oai:riunet.upv.es:10251/65130 |
| Acceso en línea: | https://riunet.upv.es/handle/10251/65130 |
| Access Level: | acceso abierto |
| Palabra clave: | IBM 4758 common cryptographic architecture Security Application Programming Interfaces (security APIs) Symbolic cryptographic protocol analysis Automatic reasoning modulo XOR theory LENGUAJES Y SISTEMAS INFORMATICOS |
| id |
ES_c7ed4d4b339ce2c187889d01f286d07f |
|---|---|
| oai_identifier_str |
oai:riunet.upv.es:10251/65130 |
| network_acronym_str |
ES |
| network_name_str |
España |
| repository_id_str |
|
| spelling |
Analysis of the IBM CCA Security API Protocols in Maude-NPAGonzález Burgueño, AntonioSantiago Pinazo, SoniaMeadows, CatherineMeseguer, JoseEscobar Román, Santiago|||0000-0002-3550-4781IBM 4758 common cryptographic architectureSecurity Application Programming Interfaces (security APIs)Symbolic cryptographic protocol analysisAutomatic reasoning modulo XOR theoryLENGUAJES Y SISTEMAS INFORMATICOSStandards for cryptographic protocols have long been attractive candidates for formal verification. It is important that such standards be correct, and cryptographic protocols are tricky to design and subject to non-intuitive attacks even when the underlying cryptosystems are secure. Thus a number of general-purpose cryptographic protocol analysis tools have been developed and applied to protocol standards. However, there is one class of standards, security application programming interfaces (security APIs), to which few of these tools have been applied. Instead, most work has concentrated on developing special-purpose tools and algorithms for specific classes of security APIs. However, there can be much advantage gained from having general-purpose tools that could be applied to a wide class of problems, including security APIs. One particular class of APIs that has proven difficult to analyze using general-purpose tools is that involving exclusive-or. In this paper we analyze the IBM 4758 Common Cryptographic Architecture (CCA) protocol using an advanced automated protocol verification tool with full exclusive-or capabilities, the Maude-NPA tool. This is the first time that API protocols have been satisfactorily specified and analyzed in the Maude-NPA, and the first time XOR-based APIs have been specified and analyzed using a general-purpose unbounded session cryptographic protocol verification tool that provides direct support for AC theories. We describe our results and indicate what further research needs to be done to make such protocol analysis generally effective.Antonio González-Burgueño, Sonia Santiago and Santiago Escobar have been partially supported by the EU (FEDER) and the Spanish MINECO under grants TIN 2010-21062-C02-02 and TIN 2013-45732-C4-1-P, and by Generalitat Valenciana PROMETEO2011/052. José Meseguer has been partially supported by NSF Grant CNS 13-10109.Springer International PublishingSpringer Lecture Notes in Computer Science, Vol. 8893Departamento de Sistemas Informáticos y ComputaciónEscuela Técnica Superior de Ingeniería InformáticaInstituto Universitario Valenciano de Investigación en Inteligencia ArtificialEuropean Regional Development FundMinisterio de Economía y CompetitividadGeneralitat ValencianaNational Science Foundation, EEUUMinisterio de Ciencia e InnovaciónRepositorio Institucional de la Universitat Politècnica de València Riunet20142014-01-01book parthttp://purl.org/coar/resource_type/c_3248info:eu-repo/semantics/bookPartapplication/pdfapplication/pdfhttps://riunet.upv.es/handle/10251/65130reponame:RiuNet. Repositorio Institucional de la Universitat Politécnica de Valénciainstname:Universitat Politècnica de València (UPV)InglésengMinisterio de Ciencia e Innovación http://dx.doi.org/10.13039/501100004837 TIN2010-21062-C02-02 SWEETLOGICS-UPVNational Science Foundation, China https://doi.org/10.13039/100000001 1319109 TWC: Small: Collaborative: Extensible Symbolic Analysis Modulo SMT: Combining the Powers of Rewriting, Narrowing, and SMT Solving in MaudeMinisterio de Economía y Competitividad http://dx.doi.org/10.13039/501100003329 TIN2013-45732-C4-1-P UNA APROXIMACION DECLARATIVA AL MODELADO, ANALISIS Y RESOLUCION DE PROBLEMASGeneralitat Valenciana https://doi.org/10.13039/501100003359 PROMETEO%2F2011%2F052 LOGICEXTREME: TECNOLOGIA LOGICA Y SOFTWARE SEGUROopen accesshttp://purl.org/coar/access_right/c_abf2Reserva de todos los derechoshttp://rightsstatements.org/vocab/InC/1.0/info:eu-repo/semantics/openAccessoai:riunet.upv.es:10251/651302026-06-13T07:49:27Z |
| dc.title.none.fl_str_mv |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| title |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| spellingShingle |
Analysis of the IBM CCA Security API Protocols in Maude-NPA González Burgueño, Antonio IBM 4758 common cryptographic architecture Security Application Programming Interfaces (security APIs) Symbolic cryptographic protocol analysis Automatic reasoning modulo XOR theory LENGUAJES Y SISTEMAS INFORMATICOS |
| title_short |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| title_full |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| title_fullStr |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| title_full_unstemmed |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| title_sort |
Analysis of the IBM CCA Security API Protocols in Maude-NPA |
| dc.creator.none.fl_str_mv |
González Burgueño, Antonio Santiago Pinazo, Sonia Meadows, Catherine Meseguer, Jose Escobar Román, Santiago|||0000-0002-3550-4781 |
| author |
González Burgueño, Antonio |
| author_facet |
González Burgueño, Antonio Santiago Pinazo, Sonia Meadows, Catherine Meseguer, Jose Escobar Román, Santiago|||0000-0002-3550-4781 |
| author_role |
author |
| author2 |
Santiago Pinazo, Sonia Meadows, Catherine Meseguer, Jose Escobar Román, Santiago|||0000-0002-3550-4781 |
| author2_role |
author author author author |
| dc.contributor.none.fl_str_mv |
Springer Lecture Notes in Computer Science, Vol. 8893 Departamento de Sistemas Informáticos y Computación Escuela Técnica Superior de Ingeniería Informática Instituto Universitario Valenciano de Investigación en Inteligencia Artificial European Regional Development Fund Ministerio de Economía y Competitividad Generalitat Valenciana National Science Foundation, EEUU Ministerio de Ciencia e Innovación Repositorio Institucional de la Universitat Politècnica de València Riunet |
| dc.subject.none.fl_str_mv |
IBM 4758 common cryptographic architecture Security Application Programming Interfaces (security APIs) Symbolic cryptographic protocol analysis Automatic reasoning modulo XOR theory LENGUAJES Y SISTEMAS INFORMATICOS |
| topic |
IBM 4758 common cryptographic architecture Security Application Programming Interfaces (security APIs) Symbolic cryptographic protocol analysis Automatic reasoning modulo XOR theory LENGUAJES Y SISTEMAS INFORMATICOS |
| description |
Standards for cryptographic protocols have long been attractive candidates for formal verification. It is important that such standards be correct, and cryptographic protocols are tricky to design and subject to non-intuitive attacks even when the underlying cryptosystems are secure. Thus a number of general-purpose cryptographic protocol analysis tools have been developed and applied to protocol standards. However, there is one class of standards, security application programming interfaces (security APIs), to which few of these tools have been applied. Instead, most work has concentrated on developing special-purpose tools and algorithms for specific classes of security APIs. However, there can be much advantage gained from having general-purpose tools that could be applied to a wide class of problems, including security APIs. One particular class of APIs that has proven difficult to analyze using general-purpose tools is that involving exclusive-or. In this paper we analyze the IBM 4758 Common Cryptographic Architecture (CCA) protocol using an advanced automated protocol verification tool with full exclusive-or capabilities, the Maude-NPA tool. This is the first time that API protocols have been satisfactorily specified and analyzed in the Maude-NPA, and the first time XOR-based APIs have been specified and analyzed using a general-purpose unbounded session cryptographic protocol verification tool that provides direct support for AC theories. We describe our results and indicate what further research needs to be done to make such protocol analysis generally effective. |
| publishDate |
2014 |
| dc.date.none.fl_str_mv |
2014 2014-01-01 |
| dc.type.none.fl_str_mv |
book part http://purl.org/coar/resource_type/c_3248 |
| dc.type.openaire.fl_str_mv |
info:eu-repo/semantics/bookPart |
| format |
bookPart |
| dc.identifier.none.fl_str_mv |
https://riunet.upv.es/handle/10251/65130 |
| url |
https://riunet.upv.es/handle/10251/65130 |
| dc.language.none.fl_str_mv |
Inglés eng |
| language_invalid_str_mv |
Inglés |
| language |
eng |
| dc.relation.none.fl_str_mv |
Ministerio de Ciencia e Innovación http://dx.doi.org/10.13039/501100004837 TIN2010-21062-C02-02 SWEETLOGICS-UPV National Science Foundation, China https://doi.org/10.13039/100000001 1319109 TWC: Small: Collaborative: Extensible Symbolic Analysis Modulo SMT: Combining the Powers of Rewriting, Narrowing, and SMT Solving in Maude Ministerio de Economía y Competitividad http://dx.doi.org/10.13039/501100003329 TIN2013-45732-C4-1-P UNA APROXIMACION DECLARATIVA AL MODELADO, ANALISIS Y RESOLUCION DE PROBLEMAS Generalitat Valenciana https://doi.org/10.13039/501100003359 PROMETEO%2F2011%2F052 LOGICEXTREME: TECNOLOGIA LOGICA Y SOFTWARE SEGURO |
| dc.rights.none.fl_str_mv |
open access http://purl.org/coar/access_right/c_abf2 Reserva de todos los derechos http://rightsstatements.org/vocab/InC/1.0/ |
| dc.rights.openaire.fl_str_mv |
info:eu-repo/semantics/openAccess |
| rights_invalid_str_mv |
open access http://purl.org/coar/access_right/c_abf2 Reserva de todos los derechos http://rightsstatements.org/vocab/InC/1.0/ |
| eu_rights_str_mv |
openAccess |
| dc.format.none.fl_str_mv |
application/pdf application/pdf |
| dc.publisher.none.fl_str_mv |
Springer International Publishing |
| publisher.none.fl_str_mv |
Springer International Publishing |
| dc.source.none.fl_str_mv |
reponame:RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia instname:Universitat Politècnica de València (UPV) |
| instname_str |
Universitat Politècnica de València (UPV) |
| reponame_str |
RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia |
| collection |
RiuNet. Repositorio Institucional de la Universitat Politécnica de Valéncia |
| repository.name.fl_str_mv |
|
| repository.mail.fl_str_mv |
|
| _version_ |
1869419220712816640 |
| score |
15,301603 |