Dolev-Yao is no better than Machiavelli

Paul F. Syverson, Catherine A. Meadows, Iliano Cervesato · 2000

We show that all attacks that can be mounted by a traditional Dolev-Yao intruder against common cryptographic protocols can be enacted by an apparently weaker `Machiavellian' adversary in which compromised principals will not share long-term secrets and will not send arbitrary messages. We also show that a Dolev-Yao adversary composed of multiple compromised principals is attack-equivalent to an adversary consisting of a single dishonest principal who is only willing to produce messages in valid protocol form.

Read the paper · More papers on PaperTik