|
ABSTRACT
Use of encryption to achieve authenticated communication in computer networks is discussed. Example protocols are presented for the establishment of authenticated connections, for the management of authenticated mail, and for signature verification and document integrity guarantee. Both conventional and public-key encryption algorithms are considered as the basis for protocols.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Branstad, D. Security aspects of computer networks, Proc. AIAA Comptr. Network Syst. Conf., April 1973, paper 73-427.
|
| |
2
|
Branstad, D. Encryption protection in computer data communications. Proc. Fourth Data Communications Symp., Oct. 1975, pp. 8.1-8.7 (available from ACM, New York).
|
| |
3
|
DiMe, W., and Hellman, M. Multiuser Cryptographic Techniques, Proc AFIPS 1976 NCC, AFIPS Press, Montvale, N.J., pp. 109-112.
|
| |
4
|
Feistel, H. Cryptographic coding for data bank privacy. Res. Rep. RC2827, IBM T.J. Watson Res. Ctr., Yorktown Heights, N.Y., March 1970.
|
| |
5
|
|
 |
6
|
|
| |
7
|
National Bureau of Standards. Data Encryption Standard. Fed. Inform. Processing Standards Pub. 46, NBS, Washington, D.C., Jan. 1977.
|
| |
8
|
Pohlig, S. Algebraic and combinatoric aspects of cryptography. Tech. Rep. No. 6602-1, Stanford Electron. Labs., Stanford, Calif., Oct. 1977.
|
 |
9
|
|
CITED BY 265
|
|
Dejan Milojicic , Gul Agha , Philippe Bernadat , Deepika Chauhan , Shai Guday , Nadeem Jamali , Dan Lambright , Franco Travostino, Case Studies in Security and Resource Management for Mobile Object Systems, Autonomous Agents and Multi-Agent Systems, v.5 n.1, p.45-79, March 2002
|
|
|
Jang Ho Lee , Atul Prakash , Trent Jaeger , Gwobaw Wu, Supporting multi-user, multi-applet workspaces in CBE, Proceedings of the 1996 ACM conference on Computer supported cooperative work, p.344-353, November 16-20, 1996, Boston, Massachusetts, United States
|
|
|
|
|
|
|
|
|
D. B. Terry , M. M. Theimer , Karin Petersen , A. J. Demers , M. J. Spreitzer , C. H. Hauser, Managing update conflicts in Bayou, a weakly connected replicated storage system, ACM SIGOPS Operating Systems Review, v.29 n.5, p.172-182, Dec. 3, 1995
|
|
|
Ray Bird , Inder Gopal , Amir Herzberg , Phil Janson , Shay Kutten , Refik Molva , Moti Yung, The KryptoKnight family of light-weight protocols for authentication and key distribution, IEEE/ACM Transactions on Networking (TON), v.3 n.1, p.31-41, Feb. 1995
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Martín Abadi , Cédric Fournet , Georges Gonthier, Authentication primitives and their compilation, Proceedings of the 27th ACM SIGPLAN-SIGACT symposium on Principles of programming languages, p.302-315, January 19-21, 2000, Boston, MA, USA
|
|
|
|
|
|
|
|
|
I. Cervesato , A. D. Jaggard , A. Scedrov , C. Walstad, Specifying Kerberos 5 cross-realm authentication, Proceedings of the 2005 workshop on Issues in the theory of security, p.12-26, January 10-11, 2005, Long Beach, California
|
|
|
|
|
|
|
|
|
J. Murai , H. Kusumoto , S. Yamaguchi , A. Kato, Construction of internet for Japanese academic communities, Proceedings of the 1989 ACM/IEEE conference on Supercomputing, p.737-746, November 12-17, 1989, Reno, Nevada, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Paul J. Leach , Bernard L. Stumpf , James A. Hamilton , Paul H. Levine, UIDs as internal names in a distributed file system, Proceedings of the first ACM SIGACT-SIGOPS symposium on Principles of distributed computing, p.34-41, August 18-20, 1982, Ottawa, Canada
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Richard A. DeMillo , Nancy A. Lynch , Michael J. Merritt, Cryptographic protocols, Proceedings of the fourteenth annual ACM symposium on Theory of computing, p.383-400, May 05-07, 1982, San Francisco, California, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
P. Lincoln , J. Mitchell , M. Mitchell , A. Scedrov, A probabilistic poly-time framework for protocol analysis, Proceedings of the 5th ACM conference on Computer and communications security, p.112-121, November 02-05, 1998, San Francisco, California, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Daniel Swinehart , Gene McDaniel , David Boggs, WFS a simple shared file system for a distributed environment, Proceedings of the seventh ACM symposium on Operating systems principles, p.9-17, December 10-12, 1979, Pacific Grove, California, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
John A. Hine , Walt Yao , Jean Bacon , Ken Moody, An architecture for distributed OASIS services, IFIP/ACM International Conference on Distributed systems platforms, p.104-120, April 03-07, 2000, New York, New York, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Karthikeyan Bhargavan , Cédric Fournet , Andrew D. Gordon , Greg O'Shea, An advisor for web services security policies, Proceedings of the 2005 workshop on Secure web services, November 11-11, 2005, Fairfax, VA, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Mihir Bellare , Ran Canetti , Hugo Krawczyk, A modular approach to the design and analysis of authentication and key exchange protocols (extended abstract), Proceedings of the thirtieth annual ACM symposium on Theory of computing, p.419-428, May 24-26, 1998, Dallas, Texas, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Anupam Datta , Ante Derek , John C. Mitchell , Dusko Pavlovic, Secure protocol composition, Proceedings of the 2003 ACM workshop on Formal methods in security engineering, p.11-23, October 30, 2003, Washington, D.C.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Karthikeyan Bhargavan , Ricardo Corin , Cédric Fournet , Andrew D. Gordon, Secure sessions for web services, Proceedings of the 2004 workshop on Secure web service, p.56-66, October 29-29, 2004, Fairfax, Virginia
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Robert Dawson , Colin Boyd , Ed Dawson , Juan Manuel González Nieto, SKMA: a key management architecture for SCADA systems, Proceedings of the 2006 Australasian workshops on Grid computing and e-research, p.183-192, January 16-19, 2006, Hobart, Tasmania, Australia
|
|
|
|
|
|
|
|
|
|
|
|
José Vicente Aguirre , Rafael Álvarez , José Noguera , Antonio Zamora, A secure remote database backup system, Proceedings of the 5th WSEAS International Conference on Artificial Intelligence, Knowledge Engineering and Data Bases, p.43-46, February 15-17, 2006, Madrid, Spain
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Randall J. Atkinson , Daniel L. McDonald , Bao G. Phan , Craig W. Metz , Kenneth C. Chin, Implementation of IPv6 in 4.4 BSD, Proceedings of the Annual Technical Conference on USENIX 1996 Annual Technical Conference, p.10-10, January 22-26, 1996, San Diego, CA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Patrick Traynor , Raju Kumar , Hussain Bin Saad , Guohong Cao , Thomas La Porta, LIGER: implementing efficient hybrid security mechanisms for heterogeneous sensor networks, Proceedings of the 4th international conference on Mobile systems, applications and services, June 19-22, 2006, Uppsala, Sweden
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Shaddin F. Doghmi , Joshua D. Guttman , F. Javier Thayer, Skeletons, Homomorphisms, and Shapes: Characterizing Protocol Executions, Electronic Notes in Theoretical Computer Science (ENTCS), 173, p.85-102, April, 2007
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Olga Kornievskaia , Peter Honeyman , Bill Doster , Kevin Coffman, Kerberized credential translation: a solution to web access control, Proceedings of the 10th conference on USENIX Security Symposium, p.18-18, August 13-17, 2001, Washington, D.C.
|
|
|
|
|
|
Ian Goldberg , Steven D. Gribble , David Wagner , Eric A. Brewer, The Ninja jukebox, Proceedings of the 2nd conference on USENIX Symposium on Internet Technologies and Systems, p.4-4, October 11-14, 1999, Boulder, Colorado
|
|
|
Ivan Cibrario Bertolotti , Luca Durante , Paolo Maggi , Riccardo Sisto , Adriano Valenzano, Improving the security of industrial networks by means of formal verification, Computer Standards & Interfaces, v.29 n.3, p.387-397, March, 2007
|
|
|
Thomas Y. C. Woo , Raghuram Bindignavle , Shaowen Su , Simon S. Lam, SNP: an interface for secure network programming, Proceedings of the USENIX Summer 1994 Technical Conference on USENIX Summer 1994 Technical Conference, p.4-4, June 06-10, 1994, Boston, Massachusetts
|
|
|
Nevin Heintze , J. D. Tygar , Jeannette Wing , H. Chi Wong, Model checking electronic commerce protocols, Proceedings of the 2nd conference on Proceedings of the Second USENIX Workshop on Electronic Commerce, p.10-10, November 18-21, 1996, Oakland, California
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Peter Honeyman , Andy Adamson , Kevin Coffman , Janani Janakiraman , Rob Jerdonek , Jim Rees, Secure videoconferencing, Proceedings of the 7th conference on USENIX Security Symposium, 1998, p.9-9, January 26-29, 1998, San Antonio, Texas
|
|
|
|
|
|
Suzana Andova , Cas Cremers , Kristian Gjøsteen , Sjouke Mauw , Stig F. Mjølsnes , Saša Radomirović, A framework for compositional verification of security protocols, Information and Computation, v.206 n.2-4, p.425-459, February, 2008
|
|
|
|
|
|
Olga Kornievskaia , Peter Honeyman , Bill Doster , Kevin Coffman, Kerberized credential translation: a solution to web access control, Proceedings of the 10th conference on USENIX Security Symposium, p.18-18, August 13-17, 2001, Washington, D.C.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Patrick Traynor , Raju Kumar , Heesook Choi , Guohong Cao , Sencun Zhu , Thomas La Porta, Efficient Hybrid Security Mechanisms for Heterogeneous Sensor Networks, IEEE Transactions on Mobile Computing, v.6 n.6, p.663-677, June 2007
|
|
|
|
|
|
|
|
|
|
|
|
Iliano Cervesato , Aaron D. Jaggard , Andre Scedrov , Joe-Kai Tsay , Christopher Walstad, Breaking and fixing public-key Kerberos, Information and Computation, v.206 n.2-4, p.402-424, February, 2008
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Karthikeyan Bhargavan , Cédric Fournet , Ricardo Corin , Eugen Zalinescu, Cryptographically verified implementations for TLS, Proceedings of the 15th ACM conference on Computer and communications security, October 27-31, 2008, Alexandria, Virginia, USA
|
|
|
Pedro Chavez Lugo , Juan J. Flores , Juan Manuel Garcia Garcia, Security architecture for a systematic administration of SELinux policies in distributed environments, Proceedings of the 7th conference on Data networks, communications, computers, p.136-143, November 07-09, 2008, Bucharest, Romania
|
|
|
|
|
|
|
|
|
Kai-Le Su , Qing-Liang Chen , Abdul Sattar , Wei-Ya Yue , Guan-Feng Lv , Xi-Zhong Zheng, Verification of authentication protocols for epistemic goals via SAT compilation, Journal of Computer Science and Technology, v.21 n.6, p.932-943, November 2006
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
INDEX TERMS
Primary Classification:
C.
Computer Systems Organization
C.2
COMPUTER-COMMUNICATION NETWORKS
C.2.0
General
Subjects:
Security and protection (e.g., firewalls)
Additional Classification:
C.
Computer Systems Organization
C.2
COMPUTER-COMMUNICATION NETWORKS
D.
Software
D.4
OPERATING SYSTEMS
D.4.6
Security and Protection
Subjects:
Authentication
E.
Data
E.3
DATA ENCRYPTION
K.
Computing Milieux
K.6
MANAGEMENT OF COMPUTING AND INFORMATION SYSTEMS
K.6.5
Security and Protection (D.4.6, K.4.2)
Subjects:
Authentication
General Terms:
Design,
Performance,
Security,
Standardization,
Theory
Keywords:
authentication,
data encryption standard,
encryption,
networks,
protocols,
public-key cryptosystems,
security
|