Simple Authentication Protocols
Mark Stamp · Information Security · 2005
This chapter provides the background needed in order to understand the real-world security protocols discussed in Chapter 10. Here, we consider several different generic ways to authenticate and establish a session key over a network. These protocols use symmetric keys, public keys or hash functions and they rely on nonces for replay prevention. We also discuss perfect forward secrecy (PFS) as well as the plusses and minuses of using timestamps in place of nonces. Throughout the chapter, we consider the broad range of attacks on protocols, including replay and tampering with the messages. We provide concrete examples that illustrate many subtle security pitfalls, which should provide some appreciation for the challenges involved in designing security protocols.