On Formal Verification Methods for Password-based Protocols: CSP/FDR and AVISPA
Abdelilah Tabet, SeongHan Shin, Kazukuni Kobara, Hideki Imai · 2005
Formal verification methods have proved a high talent in finding potential attacks automatically in several security protocols. So far, many formal methods have been proposed in the literature. In this paper we checked the abilities of two well-known checking tools, CSP/FDR and AVISPA, in detecting off-line attacks that may exist in password-based authentication protocols. For this, we apply these two formal methods to several variants of password-based protocols, vulnerable to off-line attack, so that we analyze the results and then show the weaknesses of each method.