English

Symbolic Protocol Analysis for Diffie-Hellman

Cryptography and Security 2012-02-13 v1

Abstract

We extend symbolic protocol analysis to apply to protocols using Diffie-Hellman operations. Diffie-Hellman operations act on a cyclic group of prime order, together with an exponentiation operator. The exponents form a finite field. This rich algebraic structure has resisted previous symbolic approaches. We work in an algebra defined by the normal forms of a rewriting theory (modulo associativity and commutativity). These normal forms allow us to define our crucial notion of indicator, a vector of integers that summarizes how many times each secret exponent appears in a message. We prove that the adversary can never construct a message with a new indicator in our adversary model. Using this invariant, we prove the main security goals achieved by several different protocols that use Diffie-Hellman operators in subtle ways. We also give a model-theoretic justification of our rewriting theory: the theory proves all equations that are uniformly true as the order of the cyclic group varies.

Keywords

Cite

@article{arxiv.1202.2168,
  title  = {Symbolic Protocol Analysis for Diffie-Hellman},
  author = {Daniel J. Dougherty and Joshua D. Guttman},
  journal= {arXiv preprint arXiv:1202.2168},
  year   = {2012}
}
R2 v1 2026-06-21T20:17:29.916Z