FORMAL VERIFICATION OF THE SECURE SOCKETS LAYER PROTOCOL

Llanos Tobarra, Diego Cazorla, J. José Pardo, Fernando Cuartero · 2008

Secure Sockets Layer (SSL) has become one of the most popular security protocols in the Internet. In this paper we present a formal verification of this protocol using the Casper/FDR2 toolbox. In the analysis of SSL v3.0 Handshake we have used a methodology that considers incremental versions of the protocol. We have started with the most basic protocol, and then we have included other features such as server and client authentication, digital signatures, etc. We have also verified SSL v2.0 because of the so called version rollback attack. Each version has been modelled and verified, and the results have been interpreted. Using this methodology it is easy to understand why some messages are needed in order to ensure confidential communication between a client and a server.

Read the paper · More papers on PaperTik