ScienceDirect® Home Skip Main Navigation Links
You have guest access to ScienceDirect. Find out more.
 
Home
Browse
My Settings
Alerts
Help
 Quick Search
 Search tips (Opens new window)
    Clear all fields    
Electronic Notes in Theoretical Computer Science
Volume 171, Issue 4, 10 July 2007, Pages 37-57
Proceedings of the First International Workshop on Security and Rewriting Techniques (SecReT 2006)
 
Font Size: Decrease Font Size  Increase Font Size
 Abstract - selected
Purchase PDF (441 K)

Article Toolbox
  E-mail Article   
  Add to my Quick Links   
Bookmark and share in 2collab (opens in new window)
Request permission to reuse this article
  Cited By in Scopus (0)
 
 
 
Related Articles in ScienceDirect
View More Related Articles
 
View Record in Scopus
 
doi:10.1016/j.entcs.2007.02.054    
How to Cite or Link Using DOI (Opens New Window)

Copyright © 2007 Elsevier B.V. All rights reserved.

Intruder Deduction for the Equational Theory of Exclusive-or with Commutative and Distributive Encryption1

Purchase the full-text article



References and further reading may be available for this article. To view references and further reading you must purchase this article.

Pascal Lafourcadea

aInformation Security ETH Zentrum, IFW C41.2, Haldeneggsteig 4 CH-8092 Zürich Switzerland


Available online 29 June 2007.

Abstract

The first step in the verification of cryptographic protocols is to decide the intruder deduction problem, that is the vulnerability to a so-called passive attacker. We extend the Dolev-Yao model in order to model this problem in presence of the equational theory of a commutative encryption operator which distributes over the exclusive-or operator. The interaction between the commutative distributive law of the encryption and exclusive-or offers more possibilities to decrypt an encrypted message than in the non-commutative case, which imply a more careful analysis of the proof system. We prove decidability of the intruder deduction problem for a commutative encryption which distributes over exclusive-or with a DOUBLE-EXP-TIME procedure. And we obtain that this problem is EXPSPACE-hard in the binary case.

Keywords: Cryptoprotocal verification; Dolev-Yau model; intruder detection problem

1This work was partially supported by the DGA (Contrat n° 06 60 019 00 470 75 01), the research program ACI-SI Rossignol, and the project RNTL PROUVÉ (n° 03 V 360).


Electronic Notes in Theoretical Computer Science
Volume 171, Issue 4, 10 July 2007, Pages 37-57
Proceedings of the First International Workshop on Security and Rewriting Techniques (SecReT 2006)
 
Home
Browse
My Settings
Alerts
Help
Elsevier.com (Opens new window)
About ScienceDirect  |  Contact Us  |  Information for Advertisers  |  Terms & Conditions  |  Privacy Policy
Copyright © 2008 Elsevier B.V. All rights reserved. ScienceDirect® is a registered trademark of Elsevier B.V.