“Whoa! It's like Spotify but for academic articles.”

Instant Access to Thousands of Journals for just $40/month

Get 2 Weeks Free

Verified Cryptographic Implementations for TLS

Veri ed Cryptographic Implementations for TLS ´ KARTHIKEYAN BHARGAVAN and CEDRIC FOURNET, Microsoft Research, Cambridge ˘ RICARDO CORIN and EUGEN ZALINESCU, Microsoft Research-INRIA Joint Centre, Orsay We narrow the gap between concrete implementations of cryptographic protocols and their veri ed models. We develop and verify a small functional implementation of the Transport Layer Security protocol (TLS 1.0). We make use of the same executable code for interoperability testing against mainstream implementations for automated symbolic cryptographic veri cation and automated computational cryptographic veri cation. We rely on a combination of recent tools and also develop a new tool for extracting computational models from executable code. We obtain strong security guarantees for TLS as used in typical deployments. Categories and Subject Descriptors: C.2.0 [Computer-Communication Networks]: ”Security and protection; C.2.2 [Computer-Communication Networks]: Network Protocols; D.2.4 [Software Engineering]: Software/Program Veri cation; F.3.1 [Logics and Meanings of Programs]: Specifying and Verifying and Reasoning about Programs General Terms: Security, Veri cation ACM Reference Format: Bhargavan, K., Fournet, C., Corin, R., and Zalinescu, E. 2012. Veri ed cryptographic implementations for ˘ TLS. ACM Trans. Inf. Syst. Secur. 15, 1, Article 3 (March 2012), 32 pages. DOI = 10.1145/2133375.2133378 http://doi.acm.org/10.1145/2133375.2133378 1. VERIFYING PROTOCOLS AND THEIR IMPLEMENTATIONS http://www.deepdyve.com/assets/images/DeepDyve-Logo-lg.png ACM Transactions on Information and System Security (TISSEC) Association for Computing Machinery

Loading next page...

You're reading a free preview. Subscribe to read the entire article.

And millions more from thousands of peer-reviewed journals, for just $40/month

Get 2 Weeks Free

To be the best researcher, you need access to the best research

  • With DeepDyve, you can stop worrying about how much articles cost, or if it's too much hassle to order — it's all at your fingertips. Your research is important and deserves the top content.
  • Read from thousands of the leading scholarly journals from Springer, Elsevier, Nature, IEEE, Wiley-Blackwell and more.
  • All the latest content is available, no embargo periods.