Elliptic Curve Diffie-Hellman (ECDH) is a widely adopted key exchange protocol due to its strong cryptographic security and low computational overhead. However, its implementation in various environments presents potential vulnerabilities, particularly to Man-in-the-Middle (MITM) Attacks. In this paper, the mechanism and working of ECDH are presented. The ECDH protocol has been further modeled on the AVISPA and Scyther tool. The formal security validation and analysis of ECDH on AVISPA and Scyther indicate that it suffers from Man-in-the-Middle Attack. The results highlight specific vulnerabilities in the ECDH protocol. A methodology for ECDH with Digital Certificates has been presented and the methodology has been validated on AVISPA and Scyther. The results indicate that the methodology is safe against Man-in-the-Middle Attack.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Challenges in ECDH: A Formal Validation Using AVISPA and Scyther

  • Ashaq Hussain Dar,
  • Tariq Banday,
  • Ummer Iqbal,
  • Danish Kaleem

摘要

Elliptic Curve Diffie-Hellman (ECDH) is a widely adopted key exchange protocol due to its strong cryptographic security and low computational overhead. However, its implementation in various environments presents potential vulnerabilities, particularly to Man-in-the-Middle (MITM) Attacks. In this paper, the mechanism and working of ECDH are presented. The ECDH protocol has been further modeled on the AVISPA and Scyther tool. The formal security validation and analysis of ECDH on AVISPA and Scyther indicate that it suffers from Man-in-the-Middle Attack. The results highlight specific vulnerabilities in the ECDH protocol. A methodology for ECDH with Digital Certificates has been presented and the methodology has been validated on AVISPA and Scyther. The results indicate that the methodology is safe against Man-in-the-Middle Attack.