Analysis of Nai-Wei and Alexander Authentication Protocol Using AVISPA
Andre Irawani, Nia Yulianti, Yeni Farida, Sepha Siswantyo · 2024
The BLE-Based Authentication Protocol is a mutual authentication protocol between user entities represented by a Wearable Device (WD), a Wearable Payment Counter (WP counter), and a server or trusted third party, designed by Nai-Wei and Alexander in 2020. The BLE Authentication protocol is intended to ensure authentication in Bluetooth-based micro-payment systems. According to Nai-Wei and Alexander, the BLE-Based Authentication Protocol is resistant to eavesdropping, replay attacks, man-in-the-middle attacks, and impersonation attacks. The proposed protocol claims to meet mutual authentication and backward/forward secrecy. These claims are based on analysis using the adversary model method. The protocol will be formally analyzed using AVISPA to ensure the security claims made by the BLE-Based Authentication Protocol. In this study, the validity of Nai-Wei and Alexander's claims was verified using AVISPA. The verification was conducted using the back-ends CL-AtSe and OFMC, which are capable of modelling algebraic operations in the protocol. The analysis results provided by CL-AtSe and OFMC revealed the presence of a man-in-the-middle attack. This attack is possible due to the lack of encryption and authentication factors in the message packet transmission between the WD and WP Counter. This study proposes an improved protocol scheme to address the vulnerability by adding the use of digital signatures in message packet transmissions. The improved scheme was also verified for security using AVISPA with the OFMC back-end. The verification results indicate that the improved scheme is secure against attack.