- Otway-Rees protocol
The Otway-Rees protocol is a
computer network authentication protocol designed for use oninsecure network s (eg. theInternet ). It allows individuals communicating over such a network to prove their identity to each other while also preventingeavesdropping orreplay attack s and allowing for the detection of modification.The protocol can be specified as follows in
security protocol notation , where Alice is authenticating herself to Bob using a server S (M is a session-identifier):1.
2.
3.
4.
One problem with this protocol is that a malicious intruder can arrange for A and B to end up with different keys. Here is how. After A and B execute the first three messages, B has received the key . The intruder then intercepts the fourth message. S/he resends message 2, which results in S generating a new key , subsequently sent to B. The intruder intercepts this message too, but sends to A the part of it that B would have sent to A. So now A has finally received the expected fourth message, but with instead of .
Another problem is that although the server tells B that A used a nonce, B doesn't know if this was a replay of an old message.
See also
* Kerberos
*Needham-Schroeder protocol
*Wide Mouth Frog protocol
Wikimedia Foundation. 2010.