Skip to search boxSkip to navigationSkip to main content

Formal Verification of Ephemeral Diffie-Hellman Over COSE (EDHOC)

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Publication Information

Output type

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Host publication Subtitle

4th International Conference

Original language

English

Pages from-to (Number of pages)

Pages 21-36 (15 pages)

Publication milestones

  • Published - 2018

Publication status

Published - 2018

Place of publication

Darmstadt, Germany

Publisher

Springer, United States, Germany
978-3-030-04761-0

ISBN (Electronic)

978-3-030-04762-7

Publication IDs

  • Scopus: 85057821719

Host publication title

Security Standardisation Research

Host publication editors

  • Cas Cremers
  • Anja Lehmann

Abstract

Ephemeral Diffie-Hellman over COSE (EDHOC) [1] is an authentication protocol that aims to replace TLS for resource constrained Internet of Things (IoT) devices using a selection of lightweight ciphers and formats. It is inspired by the newest Internet Draft of TLS 1.3 [2] and includes reduced round-trip modes. Unlike TLS 1.3, EDHOC is designed from scratch, and does not have to support legacy versions of the protocol. As the protocol is neither well-known nor has been used in practice it has not been scrutinized to the extent it should be.
The objective of this paper is to verify security properties of the protocol, including integrity, secrecy, and perfect forward secrecy properties. We use ProVerif [3] to analyze these properties formally. We describe violations of specific security properties for the reduced round-trip modes. The flaws were reported to the authors of the EDHOC protocol.

Publication metrics

PlumX, opens in new tab

Captures
10
Citations
15