2006-11-21 13:40:50 +00:00
|
|
|
/*
|
|
|
|
* Woo-lam version from Spore, as it is in Sjouke's list
|
|
|
|
*/
|
|
|
|
|
|
|
|
usertype Server, SessionKey, Token, Ticket;
|
|
|
|
secret k: Function;
|
|
|
|
|
|
|
|
const Simon: Server;
|
|
|
|
|
|
|
|
/* give the intruder something to work with */
|
|
|
|
// Scyther finds an attack using basic type flaws
|
|
|
|
|
|
|
|
const ke: SessionKey;
|
|
|
|
|
|
|
|
const authToken: Token;
|
|
|
|
|
|
|
|
protocol woolamcmv(A,B,S)
|
|
|
|
{
|
|
|
|
role A
|
|
|
|
{
|
2012-05-02 22:01:08 +01:00
|
|
|
fresh Na: Nonce;
|
2006-11-21 13:40:50 +00:00
|
|
|
var Nb: Nonce;
|
|
|
|
var Kab: SessionKey;
|
|
|
|
var t1,t2;
|
|
|
|
|
|
|
|
send_1(A,B, A,Na);
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_2(B,A, B,Nb);
|
2006-11-21 13:40:50 +00:00
|
|
|
send_3(A,B, { A,B, Na,Nb }k(A,S) );
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_6(B,A, { B,Na,Nb,Kab }k(A,S), { Na,Nb }Kab );
|
2006-11-21 13:40:50 +00:00
|
|
|
send_7(A,B, { Nb }Kab );
|
|
|
|
|
|
|
|
claim_8(A,Secret, Kab);
|
|
|
|
claim_9(A,Niagree);
|
|
|
|
claim_10(A,Nisynch);
|
|
|
|
}
|
|
|
|
|
|
|
|
role B
|
|
|
|
{
|
|
|
|
var Na: Nonce;
|
2012-05-02 22:01:08 +01:00
|
|
|
fresh Nb: Nonce;
|
2006-11-21 13:40:50 +00:00
|
|
|
var Kab: SessionKey;
|
|
|
|
var t1,t2;
|
|
|
|
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_1(A,B, A,Na);
|
2006-11-21 13:40:50 +00:00
|
|
|
send_2(B,A, B,Nb);
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_3(A,B, t1 );
|
2006-11-21 13:40:50 +00:00
|
|
|
send_4(B,S, t1, { A,B,Na,Nb }k(B,S) );
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_5(S,B, t2, { A,Na,Nb,Kab }k(B,S) );
|
2006-11-21 13:40:50 +00:00
|
|
|
send_6(B,A, t2, { Na,Nb }Kab );
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_7(A,B, { Nb }Kab );
|
2006-11-21 13:40:50 +00:00
|
|
|
|
|
|
|
claim_11(B,Secret, Kab);
|
|
|
|
claim_12(B,Niagree);
|
|
|
|
claim_13(B,Nisynch);
|
|
|
|
}
|
|
|
|
|
|
|
|
role S
|
|
|
|
{
|
|
|
|
var Na, Nb: Nonce;
|
2012-05-02 22:01:08 +01:00
|
|
|
fresh Kab: SessionKey;
|
2006-11-21 13:40:50 +00:00
|
|
|
|
2012-05-02 22:26:41 +01:00
|
|
|
recv_4(B,S, { A,B, Na,Nb }k(A,S), { A,B,Na,Nb }k(B,S) );
|
2006-11-21 13:40:50 +00:00
|
|
|
send_5(S,B, { B,Na,Nb,Kab }k(A,S), { A,Na,Nb,Kab }k(B,S) );
|
|
|
|
|
|
|
|
claim_14(S,Secret, Kab);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|