Protocol Interactions and the Chosen Protocol Attack

Published: 1997, Last Modified: 14 May 2025Security Protocols Workshop 1997EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: There are many cases in the literature in which reuse of the same key material for different functions can open up security holes. In this paper, we discuss such interactions between protocols, and present a new attack, called the chosen protocol attack, in which an attacker may write a new protocol using the same key material as a target protocol, which is individually very strong, but which interacts with the target protocol in a security-relevant way. We finish with a brief discussion of design principles to resist this class of attack.
Loading