Answer Posted / gtech
The Wide Mouth Frog protocol is a computer network
authentication protocol designed for use on insecure
networks (the Internet for example). It allows individuals
communicating over a network to prove their identity to each
other while also preventing eavesdropping or replay attacks,
and provides for detection of modification and the
prevention of unauthorized reading (cont)........
This can be proven using BAN logic.
The protocol can be specified as follows in security
protocol notation, where Alice is authenticating herself to
Bob using a server S:
A ightarrow S: A,{T_A, K_{AB}, B}_{K_{AS}}
S ightarrow B: {T_S, K_{AB}, A}_{K_{BS}}
Note that to prevent active attacks, some form of
authenticated encryption (or message authentication) must be
used.
The protocol has several problems:
* a global clock is required.
* the server has access to all keys.
* the value of the shared key between A and B is completely
determined by A.
* can replay messages within period when timestamp is valid.
* A is not assured that B exists.
* The protocol is stateful. This is usually undesired
because it requires more functionality and capability from
the server. For example, "S" must be able to deal with
situations in which "B" is unavailable.
------- :)---------
| Is This Answer Correct ? | 1 Yes | 0 No |
Post New Answer View All Answers
Which ipsec rule is used for the olympia branch and what does it define? (Choose two)
What is the difference between the user mode and the privileged mode?
Which ipsec rule is used for the olympia branch and what does it define?
What is STP and what is the difference between PVST and RSTP
What is the name of algorithm of eigrp protocol?
Explain the difference between named and extended acl?
On which bas ospf take decision?
What are the types of resource sharing?
Why is distributed processing useful?
What cable called v.35?
Explain the draw back of ospf protocol?
How is private ip different from public ip?
After how long keep alive messages exchange in eigrp?
Explain the types of nat?
What is the usage of service password encryption?