- Fixed ns/nsl and mpa example.

This commit is contained in:
Cas Cremers 2007-05-19 18:02:36 +02:00
parent d9d72cc417
commit f1e35b1cde
4 changed files with 60 additions and 59 deletions

View File

@ -1,54 +1,3 @@
/*
* Needham-Schroeder protocol
*/
// PKI infrastructure
const pk: Function;
secret sk: Function;
inversekeys (pk,sk);
// The protocol description
protocol ns3(I,R)
{
role I
{
const ni: Nonce;
var nr: Nonce;
send_1(I,R, {I,ni}pk(R) );
read_2(R,I, {ni,nr}pk(I) );
send_3(I,R, {nr}pk(R) );
claim_i1(I,Secret,ni);
claim_i2(I,Secret,nr);
claim_i3(I,Niagree);
claim_i4(I,Nisynch);
}
role R
{
var ni: Nonce;
const nr: Nonce;
read_1(I,R, {I,ni}pk(R) );
send_2(R,I, {ni,nr}pk(I) );
read_3(I,R, {nr}pk(R) );
claim_r1(R,Secret,ni);
claim_r2(R,Secret,nr);
claim_r3(R,Niagree);
claim_r4(R,Nisynch);
}
}
// An untrusted agent, with leaked information
const Eve: Agent;
untrusted Eve;
compromised sk(Eve);
/* /*
* Needham-Schroeder-Lowe protocol * Needham-Schroeder-Lowe protocol
*/ */
@ -68,7 +17,7 @@ protocol nsl3(I,R)
const ni: Nonce; const ni: Nonce;
var nr: Nonce; var nr: Nonce;
send_1(I,R, {I,ni}pk(R) ); send_1(I,R, {ni,I}pk(R) );
read_2(R,I, {ni,nr,R}pk(I) ); read_2(R,I, {ni,nr,R}pk(I) );
send_3(I,R, {nr}pk(R) ); send_3(I,R, {nr}pk(R) );
@ -83,7 +32,59 @@ protocol nsl3(I,R)
var ni: Nonce; var ni: Nonce;
const nr: Nonce; const nr: Nonce;
read_1(I,R, {I,ni}pk(R) ); read_1(I,R, {ni,I}pk(R) );
send_2(R,I, {ni,nr,R}pk(I) );
read_3(I,R, {nr}pk(R) );
claim_r1(R,Secret,ni);
claim_r2(R,Secret,nr);
claim_r3(R,Niagree);
claim_r4(R,Nisynch);
}
}
// An untrusted agent, with leaked information
const Eve: Agent;
untrusted Eve;
compromised sk(Eve);
/*
* Needham-Schroeder-Lowe protocol,
* broken version (wrong role name in first message)
*/
// PKI infrastructure
const pk: Function;
secret sk: Function;
inversekeys (pk,sk);
// The protocol description
protocol nsl3-broken(I,R)
{
role I
{
const ni: Nonce;
var nr: Nonce;
send_1(I,R, {ni,R}pk(R) );
read_2(R,I, {ni,nr,R}pk(I) );
send_3(I,R, {nr}pk(R) );
claim_i1(I,Secret,ni);
claim_i2(I,Secret,nr);
claim_i3(I,Niagree);
claim_i4(I,Nisynch);
}
role R
{
var ni: Nonce;
const nr: Nonce;
read_1(I,R, {ni,R}pk(R) );
send_2(R,I, {ni,nr,R}pk(I) ); send_2(R,I, {ni,nr,R}pk(I) );
read_3(I,R, {nr}pk(R) ); read_3(I,R, {nr}pk(R) );

View File

@ -17,7 +17,7 @@ protocol ns3(I,R)
const ni: Nonce; const ni: Nonce;
var nr: Nonce; var nr: Nonce;
send_1(I,R, {I,ni}pk(R) ); send_1(I,R, {ni,I}pk(R) );
read_2(R,I, {ni,nr}pk(I) ); read_2(R,I, {ni,nr}pk(I) );
send_3(I,R, {nr}pk(R) ); send_3(I,R, {nr}pk(R) );
@ -32,7 +32,7 @@ protocol ns3(I,R)
var ni: Nonce; var ni: Nonce;
const nr: Nonce; const nr: Nonce;
read_1(I,R, {I,ni}pk(R) ); read_1(I,R, {ni,I}pk(R) );
send_2(R,I, {ni,nr}pk(I) ); send_2(R,I, {ni,nr}pk(I) );
read_3(I,R, {nr}pk(R) ); read_3(I,R, {nr}pk(R) );

View File

@ -18,7 +18,7 @@ protocol nsl3-broken(I,R)
const ni: Nonce; const ni: Nonce;
var nr: Nonce; var nr: Nonce;
send_1(I,R, {R,ni}pk(R) ); send_1(I,R, {ni,R}pk(R) );
read_2(R,I, {ni,nr,R}pk(I) ); read_2(R,I, {ni,nr,R}pk(I) );
send_3(I,R, {nr}pk(R) ); send_3(I,R, {nr}pk(R) );
@ -33,7 +33,7 @@ protocol nsl3-broken(I,R)
var ni: Nonce; var ni: Nonce;
const nr: Nonce; const nr: Nonce;
read_1(I,R, {R,ni}pk(R) ); read_1(I,R, {ni,R}pk(R) );
send_2(R,I, {ni,nr,R}pk(I) ); send_2(R,I, {ni,nr,R}pk(I) );
read_3(I,R, {nr}pk(R) ); read_3(I,R, {nr}pk(R) );

View File

@ -17,7 +17,7 @@ protocol nsl3(I,R)
const ni: Nonce; const ni: Nonce;
var nr: Nonce; var nr: Nonce;
send_1(I,R, {I,ni}pk(R) ); send_1(I,R, {ni,I}pk(R) );
read_2(R,I, {ni,nr,R}pk(I) ); read_2(R,I, {ni,nr,R}pk(I) );
send_3(I,R, {nr}pk(R) ); send_3(I,R, {nr}pk(R) );
@ -32,7 +32,7 @@ protocol nsl3(I,R)
var ni: Nonce; var ni: Nonce;
const nr: Nonce; const nr: Nonce;
read_1(I,R, {I,ni}pk(R) ); read_1(I,R, {ni,I}pk(R) );
send_2(R,I, {ni,nr,R}pk(I) ); send_2(R,I, {ni,nr,R}pk(I) );
read_3(I,R, {nr}pk(R) ); read_3(I,R, {nr}pk(R) );