2006-11-21 13:40:50 +00:00
|
|
|
/*
|
|
|
|
* Needham-Schroeder symmetric
|
|
|
|
* Amended version (from Sjouke's interpret.)
|
|
|
|
*/
|
|
|
|
|
|
|
|
/* symmetric */
|
|
|
|
|
|
|
|
usertype SessionKey;
|
|
|
|
secret k: Function;
|
|
|
|
|
|
|
|
/* agents */
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
/* untrusted e */
|
|
|
|
|
|
|
|
untrusted e;
|
|
|
|
const kee: SessionKey;
|
|
|
|
|
|
|
|
compromised k(e,e);
|
|
|
|
compromised k(e,a);
|
|
|
|
compromised k(e,b);
|
|
|
|
compromised k(a,e);
|
|
|
|
compromised k(b,e);
|
|
|
|
|
|
|
|
/* {}x used for public (invertible) function modeling */
|
|
|
|
|
|
|
|
usertype PseudoFunction;
|
|
|
|
const succ: PseudoFunction;
|
|
|
|
|
|
|
|
usertype Ticket;
|
|
|
|
|
|
|
|
protocol nssymmetricamended(A,S,B)
|
|
|
|
{
|
|
|
|
role A
|
|
|
|
{
|
2012-05-02 22:01:08 +01:00
|
|
|
fresh na: Nonce;
|
2006-11-21 13:40:50 +00:00
|
|
|
var T1: Ticket;
|
|
|
|
var T2: Ticket;
|
|
|
|
var kab: SessionKey;
|
|
|
|
var nb: Nonce;
|
|
|
|
|
|
|
|
send_1(A,B, A );
|
|
|
|
read_2(B,A, T1 );
|
|
|
|
send_3(A,S, A,B,na,T1 );
|
|
|
|
read_4(S,A, { na,B,kab,T2 }k(A,S) );
|
|
|
|
send_5(A,B, T2 );
|
|
|
|
read_6(B,A, { nb }kab );
|
|
|
|
send_7(A,B, { {nb}succ }kab );
|
|
|
|
|
|
|
|
claim_8(A, Secret, kab);
|
|
|
|
claim_8a(A, Niagree);
|
|
|
|
claim_8b(A, Nisynch);
|
|
|
|
}
|
|
|
|
|
|
|
|
role S
|
|
|
|
{
|
2012-05-02 22:01:08 +01:00
|
|
|
fresh kab: SessionKey;
|
2006-11-21 13:40:50 +00:00
|
|
|
var na: Nonce;
|
|
|
|
var nb: Nonce;
|
|
|
|
|
|
|
|
read_3(A,S, A,B,na, { A,nb }k(B,S) );
|
|
|
|
send_4(S,A, { na,B,kab, { kab,A }k(B,S) }k(A,S) );
|
|
|
|
}
|
|
|
|
|
|
|
|
role B
|
|
|
|
{
|
|
|
|
var kab: SessionKey;
|
2012-05-02 22:01:08 +01:00
|
|
|
fresh nb: Nonce;
|
2006-11-21 13:40:50 +00:00
|
|
|
|
|
|
|
read_1(A,B, A );
|
|
|
|
send_2(B,A, { A,nb }k(B,S) );
|
|
|
|
read_5(A,B, { kab,A }k(B,S) );
|
|
|
|
send_6(B,A, { nb }kab );
|
|
|
|
read_7(A,B, { {nb}succ }kab );
|
|
|
|
|
|
|
|
claim_9(B, Secret, kab);
|
|
|
|
claim_9a(B, Niagree);
|
|
|
|
claim_9b(B, Nisynch);
|
|
|
|
}
|
|
|
|
}
|