Needham and Schroeder suggest the following variant of their protocol: 1. Alice → Bob : Alice 2. Bob→ Alice: {Alice rand3}kBob 3. Alice→Cathy: {Alice Bob rand₁ |{Alice rand3}kBob} 4. Cathy → Alice: {Alice Bob rand1 ksession {Alice rand3|ksession}KBob}kAlice 5. Alice → Bob: {Alice rand3|ksession}KBob 6. Bob→ Alice: {rand2}ksession 7. Alice → Bob: {rand2-1}ksession Show that this protocol solves the problem of replay as a result of stolen session keys. Hint: Consider two cases, one in which the attacker does not send an initial message to Bob and one in which the attacker does.

Database System Concepts
7th Edition
ISBN:9780078022159
Author:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Chapter1: Introduction
Section: Chapter Questions
Problem 1PE
icon
Related questions
Question
Needham and Schroeder suggest the following variant of their protocol:
1. Alice → Bob : Alice
2. Bob→ Alice: {Alice rand3}kBob
3. Alice → Cathy : {Alice Bob rand₁|{Alice rand3}kBob}
4. Cathy → Alice: {Alice Bob rand₁|ksession|{Alice rand3|ksession}KBob}KAlice
5. Alice → Bob: {Alice rand3|ksession}kBob
6. Bob→ Alice: {rand2}ksession
7. Alice → Bob: {rand2-1}ksession
Show that this protocol solves the problem of replay as a result of stolen session keys.
Hint: Consider two cases, one in which the attacker does not send an initial message to Bob and one in which
the attacker does.
Transcribed Image Text:Needham and Schroeder suggest the following variant of their protocol: 1. Alice → Bob : Alice 2. Bob→ Alice: {Alice rand3}kBob 3. Alice → Cathy : {Alice Bob rand₁|{Alice rand3}kBob} 4. Cathy → Alice: {Alice Bob rand₁|ksession|{Alice rand3|ksession}KBob}KAlice 5. Alice → Bob: {Alice rand3|ksession}kBob 6. Bob→ Alice: {rand2}ksession 7. Alice → Bob: {rand2-1}ksession Show that this protocol solves the problem of replay as a result of stolen session keys. Hint: Consider two cases, one in which the attacker does not send an initial message to Bob and one in which the attacker does.
Expert Solution
Step 1

Stolen Session key:-

In the field of computer science, session hijacking, also referred to as cookie hijacking, is the use of a legitimate computer session, also known as a session key, to obtain unauthorized access to data or services in a computer system. The theft of a magic cookie, which is used to authenticate a user to a remote service, is specifically mentioned. It is especially pertinent to web developers since many websites employ HTTP cookies to maintain sessions, which can be readily taken by an attacker using a third-party computer or with access to the victim's computer's saved cookies (see HTTP cookie theft).

steps

Step by step

Solved in 2 steps

Blurred answer
Knowledge Booster
Network Transmission Cabling
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, computer-science and related others by exploring similar questions and additional content below.
Similar questions
Recommended textbooks for you
Database System Concepts
Database System Concepts
Computer Science
ISBN:
9780078022159
Author:
Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:
McGraw-Hill Education
Starting Out with Python (4th Edition)
Starting Out with Python (4th Edition)
Computer Science
ISBN:
9780134444321
Author:
Tony Gaddis
Publisher:
PEARSON
Digital Fundamentals (11th Edition)
Digital Fundamentals (11th Edition)
Computer Science
ISBN:
9780132737968
Author:
Thomas L. Floyd
Publisher:
PEARSON
C How to Program (8th Edition)
C How to Program (8th Edition)
Computer Science
ISBN:
9780133976892
Author:
Paul J. Deitel, Harvey Deitel
Publisher:
PEARSON
Database Systems: Design, Implementation, & Manag…
Database Systems: Design, Implementation, & Manag…
Computer Science
ISBN:
9781337627900
Author:
Carlos Coronel, Steven Morris
Publisher:
Cengage Learning
Programmable Logic Controllers
Programmable Logic Controllers
Computer Science
ISBN:
9780073373843
Author:
Frank D. Petruzella
Publisher:
McGraw-Hill Education