Model Checking the IKEv2 Protocol Using Spin

Ninet, Tristan;Legay, Axel;Maillard, Romaric;Traonouez, Louis-Marie;Zendra, Olivier
(2019) 2019 17th International Conference on Privacy, Security and Trust (PST) — Location: Fredericton, NB, Canada (26.August.2019)

Files

pst.pdf
  • Open Access
  • Adobe PDF
  • 158.44 KB

Details

Authors
  • Ninet, Tristan
    Author
  • Legay, AxelUCLouvain
    Author
  • Maillard, Romaric
    Author
  • Traonouez, Louis-Marie
    Author
  • Zendra, Olivier
    Author
Abstract
Previous analyses of IKEv2 concluded that the protocol was suffering from two authentication vulnerabilities: the penultimate authentication flaw and a vulnerability that leads to a reflection attack. In this paper we analyze the IKEv2 protocol specification using the Spin model checker. To do so, we extend and improve an existing modeling method that allows analyzing security protocols using Spin. For completeness, we indicate each abstraction we make when writing the model. As a result, we show that the reflection attack is actually not applicable. We further discuss two modifications of the protocol and prove that both of them do overcome the penultimate authentication flaw.
Affiliations

Citations

Ninet, T., Legay, A., Maillard, R., Traonouez, L.-M., & Zendra, O. (2019). Model Checking the IKEv2 Protocol Using Spin. 2019 17th International Conference on Privacy, Security and Trust (PST). Published. 2019 17th International Conference on Privacy, Security and Trust (PST), Fredericton, NB, Canada. https://doi.org/10.1109/pst47121.2019.8949057