This description was written by a machine and published without a person checking it. It is what the agent made of this grouping, and not a statement anybody has stood behind.

Who you are talking to

A subject the papers are about. The loosest grouping, and the one to reach for last.

How two parties who have never met agree a key and learn whom they are talking to. Needham-Schroeder is what everyone built on; the rest is the field finding that such protocols fail quietly, and that a logic pronouncing one sound is not the same as its being sound.

The title's seventeen years are 1978 to 1995, and the arithmetic needs one qualification. Denning and Sacco broke a Needham-Schroeder protocol in 1981, three years in, by observing that a compromised session key stays usable -- which is what the timestamps in their title are for. But that is the symmetric-key protocol; Lowe's 1995 attack is on the public-key one, and it is that protocol which stood unchallenged for seventeen years. The set holds both breaks, and a reader should not merge them.

The sharpest record here is Burrows, Abadi and Needham in 1990, and it is sharp because of where it sits. BAN logic was applied to Needham-Schroeder and pronounced it sound, five years before Lowe found the attack. The logic was not wrong; its assumptions did not include the case Lowe exploited. That is the difference between a proof and a guarantee, stated by an example rather than an argument, and it is why this set belongs beside `do-formal-methods-pay` rather than only beside the cryptography.

Diffie and Hellman open the set because the problem only exists once key agreement without a prior meeting is possible.

Lowe is held twice: the 1995 Information Processing Letters note that states the attack, and the 1996 TACAS paper that gives the fix and the mechanical check which found it. The two are now linked -- cite the first for priority, the second for the method.

6 references

Breaking and fixing the Needham-Schroeder Public-Key Protocol using FDR
Gavin Lowe (1996) · Tools and Algorithms for the Construction and Analysis of Systems · Springer
An attack on the Needham-Schroeder public-key authentication protocol
Gavin Lowe (1995) · Information Processing Letters · Elsevier
A logic of authentication
Michael Burrows and others (1990) · ACM Transactions on Computer Systems · Association for Computing Machinery
Timestamps in key distribution protocols
Dorothy E. Denning and others (1981) · Communications of the ACM · Association for Computing Machinery
Using encryption for authentication in large networks of computers
Roger M. Needham and others (1978) · Communications of the ACM · Association for Computing Machinery
New directions in cryptography
Whitfield Diffie and others (1976) · IEEE Transactions on Information Theory · IEEE