Directory

Encyclopedia

NodeWorks
                              ENCYCLOPEDIA

Link Checker

Home
Encyclopedia : O : OT : OTW :

Otway-Rees

 

Otway-Rees

Otway-Rees is a computer network authentication protocol designed for use on insecure networks (the Internet for example). It allows individuals communicating over a network to prove their identity to each other while also preventing evesdropping or replay attacks, and provides for detection of modification and the prevention of unauthorized reading.

The protocol can be specified as follows in security protocol notation, where Alice is authenticating herself to Bob using a server S:

1.

2.

3.

4.


One problem with this protocol is that a malicious intruder can arrange for A and B to end up with different keys. Here is how. A and B execute the first three messages; at this point, B has received the key . The intruder intercepts the fourth message. S/he replays message 3, which results in S generating a new key and sending it to B. The intruder intercepts this message too, but sends to A the part of it that B would have sent to A. So now A has finally received the expected fourth message, but with instead of .


Another problem is that although the server tells B that A used a nonce, B doesn't know if this was a replay of an old message.

See also: Kerberos, Needham-Schroeder, Wide Mouth Frog.


NodeWorks boosts web surfing!
Page Returned in 0.128 seconds - HTML Compressed 68.4%

This article is from Wikipedia. All text is available
under the terms of the GNU Free Documentation License.
 GNU Free Documentation License
© 2008 Chamas Enterprises Inc.