This paper reports an analysis of the security of the Trust and Security Management (TSM) protocol, an authentication protocol which is part of the Parlay/OSA Application Program Interfaces (APIs). Parlay/OSA APIs allow third party service providers to develop new services that can access, in a controlled and secure way, the network capabilities offered by the network operator. The role of the TSM protocol, run by network gateways, is to authenticate the client applications trying to access and to use the services offered. For this reason, potential security flaws in the authentication protocol can lead to unauthorized use of the network with evident damages to the operator and to the quality of services. This paper shows how a rigorous formal analysis of the TSM protocol allowed us to discover serious weaknesses in the model describing its authentication procedure. The paper reports on the design activity of the formal model, the toolaided verification we carried out and the security flaws we discovered. This allows us to discuss how the security of the TSM protocol can be generally improved.

Security analysis of parlay/OSA framework

Gnesi S;
2004

Abstract

This paper reports an analysis of the security of the Trust and Security Management (TSM) protocol, an authentication protocol which is part of the Parlay/OSA Application Program Interfaces (APIs). Parlay/OSA APIs allow third party service providers to develop new services that can access, in a controlled and secure way, the network capabilities offered by the network operator. The role of the TSM protocol, run by network gateways, is to authenticate the client applications trying to access and to use the services offered. For this reason, potential security flaws in the authentication protocol can lead to unauthorized use of the network with evident damages to the operator and to the quality of services. This paper shows how a rigorous formal analysis of the TSM protocol allowed us to discover serious weaknesses in the model describing its authentication procedure. The paper reports on the design activity of the formal model, the toolaided verification we carried out and the security flaws we discovered. This allows us to discuss how the security of the TSM protocol can be generally improved.
2004
Istituto di Scienza e Tecnologie dell'Informazione "Alessandro Faedo" - ISTI
Security
File in questo prodotto:
File Dimensione Formato  
prod_91106-doc_125515.pdf

solo utenti autorizzati

Descrizione: Security Analysis of Parlay/OSA Framework
Tipologia: Versione Editoriale (PDF)
Dimensione 134.06 kB
Formato Adobe PDF
134.06 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/57563
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact