Formal security analysis of registration protocols for interactive systems: a methodology and a case of study
Jesus Diaz, David Arroyo, Francisco B. Rodriguez

TL;DR
This paper introduces a formal methodology for analyzing registration protocols, exemplified by CHAT-SRP, which enhances security and usability in interactive systems through cryptographically robust identity distribution and ticketing.
Contribution
It presents a novel formal analysis methodology for registration protocols and applies it to CHAT-SRP, demonstrating its security and practical benefits.
Findings
Formal verification confirms security properties of CHAT-SRP.
Tickets link users securely to registration requests.
Methodology can be applied to other communication protocols.
Abstract
In this work we present and formally analyze CHAT-SRP (CHAos based Tickets-Secure Registration Protocol), a protocol to provide interactive and collaborative platforms with a cryptographically robust solution to classical security issues. Namely, we focus on the secrecy and authenticity properties while keeping a high usability. In this sense, users are forced to blindly trust the system administrators and developers. Moreover, as far as we know, the use of formal methodologies for the verification of security properties of communication protocols isn't yet a common practice. We propose here a methodology to fill this gap, i.e., to analyse both the security of the proposed protocol and the pertinence of the underlying premises. In this concern, we propose the definition and formal evaluation of a protocol for the distribution of digital identities. Once distributed, these identities can…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Authentication Protocols Security · User Authentication and Security Systems · Cryptography and Data Security
