On the Verification of Cryptographic Protocols
Dieter Gollmann · Electronic Notes in Theoretical Computer Science · 2000
There is a mantra telling us that authentication is difficult. The failure to design robust authentication protocols is commonly attributed to a lack of good design strategies, and to a lack of verification tools. We will argue that the problem is rather confusion about the meaning of ‘authentication’. If you do not know what you are aiming for, what hope is there in achieving ‘it’? Imprecise and anthropomorphic terminology does not help to clarify technical issues, and confusion about the goals of entity authentication has misled attempts to formalize this concept.