Who you are talking to
A subject the papers are about. The loosest grouping, and the one to reach for last.
How two parties who have never met agree a key and learn whom they are talking to. Needham-Schroeder is what everyone built on; the rest is the field finding that such protocols fail quietly, and that a logic pronouncing one sound is not the same as its being sound.
The title's seventeen years are 1978 to 1995, and the arithmetic needs one qualification. Denning and Sacco broke a Needham-Schroeder protocol in 1981, three years in, by observing that a compromised session key stays usable -- which is what the timestamps in their title are for. But that is the symmetric-key protocol; Lowe's 1995 attack is on the public-key one, and it is that protocol which stood unchallenged for seventeen years. The set holds both breaks, and a reader should not merge them.
The sharpest record here is Burrows, Abadi and Needham in 1990, and it is sharp because of where it sits. BAN logic was applied to Needham-Schroeder and pronounced it sound, five years before Lowe found the attack. The logic was not wrong; its assumptions did not include the case Lowe exploited. That is the difference between a proof and a guarantee, stated by an example rather than an argument, and it is why this set belongs beside `do-formal-methods-pay` rather than only beside the cryptography.
Diffie and Hellman open the set because the problem only exists once key agreement without a prior meeting is possible.
Lowe is held twice: the 1995 Information Processing Letters note that states the attack, and the 1996 TACAS paper that gives the fix and the mechanical check which found it. The two are now linked -- cite the first for priority, the second for the method.