Composable Formal Security Analysis: Juggling Soundness, Simplicity and Efficiency

  • Authors:
  • Ran Canetti

  • Affiliations:
  • IBM Research,

  • Venue:
  • ICALP '08 Proceedings of the 35th international colloquium on Automata, Languages and Programming, Part II
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

A security property of a protocol is composableif it remains intact even when the protocol runs alongside other protocols in the same system. We describe a method for asserting composable security properties, and demonstrate its usefulness. In particular, we show how this method can be used to provide security analysis that is formal, relatively simple, and still does not make unjustified abstractions of the underlying cryptographic algorithms in use. It can also greatly enhance the feasibility of automatedsecurity analysis of systems of realistic size.