Applying NCP Logic to the Analysis of SSL 3.0

  • Authors:
  • Zhimin Song;Sihan Qing

  • Affiliations:
  • -;-

  • Venue:
  • ICICS '01 Proceedings of the Third International Conference on Information and Communications Security
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we use extended NCP logic to formally analyze SSL 3.0, and show two important weak points of the protocol, which are the server's not assured of the freshness and the origin of the pre-master secret when RSA is used for key exchange. We only give specification and analysis of one authentication mode of SSL 3.0 in detail, but all authentication modes have the two weak points. Especially, the flaw of the freshness of the pre-master secret may result in reuse of the pre-master secret, and we properly remedy it by introducing a nonce.