Analyzing MORNeS Protocol for Secure Key Exchange with BAN Logic
Khairil Ahmad, Jafaruddin Gusti Amri Ginting, Cahya Damarjati, Eko Fajar Cahyadi · 2025
The distribution of secure session keys and mutual authentication are essential prerequisites in distributed computing systems, where sensitive data are transmitted over untrusted networks. The Modified Otway-Rees and Needham-Schroeder (MORNeS) protocol integrates the advantages of the Otway-Rees and Needham-Schroeder schemes to provide secure session key distribution and mutual authentication. MORNeS improves replay and man-in-the-middle attacks resistance. Nevertheless, it remains vulnerable to reflection-based exploitation due to its symmetric challenge-response architecture. This study performs a formal analysis of MORNeS employing BAN logic to meticulously assess its security guarantees. The study verified that the protocol fulfills essential requirements, such as mutual authentication, confidentiality, freshness, and replay resistance, while maintaining the secrecy of session keys between communication parties. Nevertheless, the work underscores a significant vulnerability, wherein adversaries may leverage nonce reflection to circumvent authentication without possessing the real session key. To mitigate this restriction, we suggest improvements including nonce translation, asymmetric challenge-response techniques, and sessionspecific message binding. These adjustments substantially improve robustness with negligible computational expense. This work improves key distribution for safe, efficient and scalable communication in distributed systems by merging formal security validation with practical design improvements, providing significant information for future protocol development.