Arrangementet giver en introduktion til moderne teknikker og metoder til beskrivelse og analyse af sikkerhedsprotokoller i netværk. Endvidere gives eksempler på deres anvendelse - herunder sikkerhedslaget i ZigBee protokollen, som er udbredt indenfor 'Home Automation'.
Der findes en række teknikker til modellering og verifikation af sikkerhedsprotokoller, og på dette seminar præsenteres en af de mest anvendte, nemlig statisk anlyse. Teknikken illustreres gennem anvendelse på ZigBee standarden. Endvidere gives en generel introduktion til protokol modellering, og der gives også en introduktion til 'Universal Composability', som anvendes til beskrivelse af de angreb, som sikkerhedsprotokoller kan blive udsat for.
Program
1. Velkomst
2. Arne Skou, CISS: Introduction to Protocol Modelling
3. Ender Yuksel, IMM/DTU: Modelling and Verification of ZigBee Security Sublayer
4. Jesper Buus Nielsen, DAIMI/AU: Universal Composability of Security Protocols
5. Discussion and Networking
Ender Yuksels abstract:
ZigBee, whose name is derived from the zigzag dance of bees that enable them to share information, is a low cost and low power consumption Wireless Personal Area Network (low-rate WPAN) standard, which can be used in many applications such as home/building automation, consumer electronics, industrial controls, PC peripherals, medical sensor applications, toys, etc.
ZigBee Security Sublayer defines the security protocols that will be used to secure the communication between ZigBee devices.
Jesper Buus Nielsens abstract:
In recent years the framework of Universally Composable Security developed at the IBM T.J. Watson Research Center has become the de factor standard in cryptography for stating and proving security properties about cryptographic protocols. One of the reasons being that it is considered one, if not the only, cryptographic model that guarantees security which is sufficient for complex environments like the Internet.
This talk explains the basics of the UC framework and explains why it has become as widely popular as it has. We also look at some of the applications that the UC framework has had and look upon the relations between formal analysis and automated analysis of cryptographic protocols and the UC framework.
Målgruppe:
Softwareudviklere og -arkitekter med interesse for sikkerhed i netværksprotokoller. Forudsætninger for deltagelse er en generel viden om netværksprotokoller og software.