Security Challenges in ECDH: A Formal Validation Using AVISPA and Scyther
摘要
Elliptic Curve Diffie-Hellman (ECDH) is a widely adopted key exchange protocol due to its strong cryptographic security and low computational overhead. However, its implementation in various environments presents potential vulnerabilities, particularly to Man-in-the-Middle (MITM) Attacks. In this paper, the mechanism and working of ECDH are presented. The ECDH protocol has been further modeled on the AVISPA and Scyther tool. The formal security validation and analysis of ECDH on AVISPA and Scyther indicate that it suffers from Man-in-the-Middle Attack. The results highlight specific vulnerabilities in the ECDH protocol. A methodology for ECDH with Digital Certificates has been presented and the methodology has been validated on AVISPA and Scyther. The results indicate that the methodology is safe against Man-in-the-Middle Attack.