期刊文献+

一种分析电子商务安全协议的新逻辑 被引量:1

New Logic of Analyzing Electronic Commerce Security Protocols
下载PDF
导出
摘要 针对典型电子商务安全协议逻辑分析方法存在的问题,如安全属性分析存在局限性、缺乏形式化语义、对混合密码原语的处理能力不强等,提出了一种新的逻辑分析方法。新逻辑能够分析电子商务安全协议的认证性、密钥保密性、非否认性、可追究性、公平性及原子性。以匿名电子现金支付协议ISI作为分析实例,证明了新逻辑方法的有效性。分析找出了该协议的安全漏洞和缺陷:不满足商家的非否认性、密钥保密性、可追究性、公平性以及原子性,客户面临商家恶意欺骗的潜在威胁。 The paper researched the typical logic analysis methods of electronic commerce security protocols and pointed out their limitations in analyzing security properties.Most of them are lack of formal semantics and ability of analyzing hybrid cryptography-based primitives.In response on the above-mentioned problems,the paper proposed a new logic analysis method,which can analyze most of the known security properties of the electronic commerce protocols,such as authentication,secrecy of key,non-repudiation,accountability,fairness and atomicity.The validation of the new logic was verified by analyzing the anonymous e-cash payment protocol ISI.The analysis reveals the security vulnerabilities and flaws of the protocol,which cannot satisfy non-repudiation of merchants,secrey of key,accountability,fairness and atomicity,moreover,the customers face malicious cheat of the merchants.
作者 陈莉
出处 《计算机科学》 CSCD 北大核心 2010年第10期110-115,共6页 Computer Science
基金 国家高技术研究发展计划(863计划)(2007AA01Z471) 国家自然科学基金项目(60473021) 河南省重点科技攻关项目(072102210029) 河南省科技攻关项目(0624260017)资助
关键词 逻辑分析方法 安全属性 密钥保密性 原子性 混合密码原语 逻辑构件 Logic analysis method Security property Secrey of key Atomicity Hybrid cryptography-based primitives Logic sentences
  • 相关文献

参考文献9

  • 1Kailar R. Accountability in Electronic Commerce Protocols [J]. IEEE Transactions on Software Engineering, 1996,22 (5):313- 328.
  • 2Syverson P F, van Oorschot P C. On unifying some cryptographic protocol[A]//Proeeedings of the IEEE 1994 Computer Society Symposium in Security and Privacy [C]. Los Alamitos. IEEE Computer Society Press, 1994:14-28.
  • 3卿斯汉.一种电子商务协议形式化分析方法[J].软件学报,2005,16(10):1757-1765. 被引量:23
  • 4王彩芬,葛建华.一种分析电子商务协议的新方法[J].计算机学报,2004,27(4):507-515. 被引量:10
  • 5王茜,杨德礼.一种基于SVO逻辑的新形式化验证方法[J].计算机集成制造系统-CIMS,2004,10(3):342-351. 被引量:6
  • 6黎波涛,罗军舟.不可否认协议时限性的形式化分析[J].软件学报,2006,17(7):1510-1516. 被引量:13
  • 7Knowledge S P. belief, and semantics in the analysis of cryptographic protocols[J]. Journal of Computer Security, 1992,1 (3) : 317-334.
  • 8Camap R. Meaning And Neeessity-A Study in Semantics and Modal logic[M]. Clarke Press, 2007.
  • 9Medvinsky G, Neuman B C. Netcash: a design of practical electronic currency on the Internet [A]//Proceedings of the First ACM Conference on Computer and Communications Security [C]. USA: ACM Press, 1993: 102-106.

二级参考文献53

  • 1范红,冯登国.一个非否认协议ZG的形式化分析[J].电子学报,2005,33(1):171-173. 被引量:8
  • 2卿斯汉,李改成.公平交换协议的一个形式化模型[J].中国科学(E辑),2005,35(2):161-172. 被引量:9
  • 3[1]WANG Qian, YANG Deli. The study on atomic electronic cash protocol[A].Proceedings of International Symposium on Future Software Technology[C]. Wuhan: HUST Press,2002.26-29.
  • 4[2]CAMP J, HARKAVY M,TYGAR J D, YEE B. Anonymous atomic transactions[A]. Proceeding of the 2nd Usenix Workshop on Electronic Commerce[C].ACM Press,1996.123-133.
  • 5[3]CAMP J. An atomcity-generating protocol for anonymous currencies[J]. IEEE Transactions on Software Engineering, 2001,27(3):272-278.
  • 6[4]WANG Qian, YANG Deli. The research of dual-mode electronic cash system[A]. Proceedings of 2002 International Conference on Management Science&Engineering[C].Harbin:Harbin Institute of Technology Press,2002.1609-1613.
  • 7[5]BURROWS M, ABADI M, NEEDHAM R M. A logic of authentication[J]. ACM Transacion on Computer System,1990, 8 (1):18-36.
  • 8[6]BURMESTER M. On the risk of opening distributed keys[A]. In Advanced in Cryptology-CRYPTO'94[C]. Berlin: Springer-Verlag, LNCS (839),1994.308-317.
  • 9[7]NEUMAN B C, THEODORE,T S. An authentication service for compute network[J]. IEEE Communication Magazine,1990, 132(9):33-38.
  • 10[8]BOYD C, MAN W. On a limitation of BAN logic[A]. In Advances in Cryptology-Eurocrypt'93, Vol 765 of Lecture Notes in Computer Science[C]. Berlin:Springer-Verlag,1993.240-247.

共引文献43

同被引文献9

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部