Protocol failures in cryptosystems
Judy H. Moore · Proceedings of the IEEE · 1988
When a cryptoalgorithm is used to solve data security or authentication problems, it is implemented within the context of a protocol that specifies the appropriate procedures for data handling. The purpose of the protocol is to ensure that when the cryptosystem is applied, the level of security or authentication required by the system is actually attained. The author surveys a collection of protocols in which this goal has not been met, not because of a failure of the cryptoalgorithm used, but rather because of shortcomings in the design of the protocol. Guidelines for the development of sound protocols are extracted from an analysis of these failures.>