Computationally Sound Verification of Source Code

被引:23
作者
Backes, Michael [1 ]
Maffei, Matteo [2 ]
Unruh, Dominique [2 ]
机构
[1] Univ Saarland, MPI SWS, D-66123 Saarbrucken, Germany
[2] Univ Saarland, D-66123 Saarbrucken, Germany
来源
PROCEEDINGS OF THE 17TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'10) | 2010年
关键词
Computational soundness; verification; source code; SYMMETRIC-ENCRYPTION; SECURITY;
D O I
10.1145/1866307.1866351
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Increasing attention has recently been given to the formal verification of the source code of cryptographic protocols. The standard approach is to use symbolic abstractions of cryptography that make the analysis amenable to automation. This leaves the possibility of attacks that exploit the mathematical properties of the cryptographic algorithms themselves. In this paper, we show how to conduct the protocol analysis on the source code level (F# in our case) in a computationally sound way, i.e., taking into account cryptographic security definitions. We build upon the prominent F7 verification framework (Bengtson et al., CSF 2008) which comprises a security type-checker for F# protocol implementations using symbolic idealizations and the concurrent lambda calculus RCF to model a core fragment of F#. To leverage this prior work, we give conditions under which symbolic security of RCF programs using cryptographic idealizations implies computational security of the same programs using cryptographic algorithms. Combined with F7, this yields a computationally sound, automated verification of F# code containing public-key encryptions and signatures. For the actual computational soundness proof, we use the CoSP framework (Backes, Hofheinz, and Unruh, CCS 2009). We thus inherit the modularity of CoSP, which allows for easily extending our proof to other cryptographic primitives.
引用
收藏
页码:387 / 398
页数:12
相关论文
共 40 条
  • [11] Backes M, 2009, CCS'09: PROCEEDINGS OF THE 16TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, P66
  • [12] Backes Michael, LIB SOURCE CODE F7 T
  • [13] Backes Michael, 2010, 2014416 IACR EPRINT
  • [14] Basin D., 2004, INT J INFORM SECURIT
  • [15] Baudet M, 2005, LECT NOTES COMPUT SC, V3580, P652
  • [16] Refinement types for secure implementations
    Bengtson, Jesper
    Bhargavan, Karthikeyan
    Fournet, Cedric
    Gordon, Andrew D.
    Maffeis, Sergio
    [J]. CSF 2008: 21ST IEEE COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, PROCEEDINGS, 2008, : 17 - +
  • [17] Bhargavan K., 2010, P 37 S PRINC PROGR L
  • [18] Bhargavan K., P 19 IEEE COMP SEC F, P139
  • [19] Bhargavan K, 2008, CCS'08: PROCEEDINGS OF THE 15TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, P459
  • [20] An efficient cryptographic protocol verifier based on prolog rules
    Blanchet, B
    [J]. 14TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2001, : 82 - 96