Skip to main content
QUICK REVIEW

[논문 리뷰] Actor-network procedures: Modeling multi-factor authentication, device pairing, social interactions

Duško Pavlović, Catherine Meadows|arXiv (Cornell University)|2011. 06. 03.
User Authentication and Security Systems참고 문헌 65인용 수 10
한 줄 요약

이 논문은 인간, 장치, 통신 채널을 통합하는 이질적 네트워크를 위한 형식적 모델로 액터-네트워크 절차를 도입하고, 이러한 시스템에서의 보안을 추론하기 위해 절차 유도 논리(PDL)를 제안한다. 이 프레임워크는 이중 인증과 다중 채널 장치 쌍화를 분석하여, 지역적 제약 조건을 통해 통합된 논리적 및 다이어그램적 추론을 통해 전역적 보안 성질을 보장할 수 있음을 보여준다.

ABSTRACT

As computation spreads from computers to networks of computers, and migrates into cyberspace, it ceases to be globally programmable, but it remains programmable indirectly: network computations cannot be controlled, but they can be steered by local constraints on network nodes. The tasks of "programming" global behaviors through local constraints belong to the area of security. The "program particles" that assure that a system of local interactions leads towards some desired global goals are called security protocols. As computation spreads beyond cyberspace, into physical and social spaces, new security tasks and problems arise. As networks are extended by physical sensors and controllers, including the humans, and interlaced with social networks, the engineering concepts and techniques of computer security blend with the social processes of security. These new connectors for computational and social software require a new "discipline of programming" of global behaviors through local constraints. Since the new discipline seems to be emerging from a combination of established models of security protocols with older methods of procedural programming, we use the name procedures for these new connectors, that generalize protocols. In the present paper we propose actor-networks as a formal model of computation in heterogenous networks of computers, humans and their devices; and we introduce Procedure Derivation Logic (PDL) as a framework for reasoning about security in actor-networks. On the way, we survey the guiding ideas of Protocol Derivation Logic (also PDL) that evolved through our work in security in last 10 years. Both formalisms are geared towards graphic reasoning and tool support. We illustrate their workings by analysing a popular form of two-factor authentication, and a multi-channel device pairing procedure, devised for this occasion.

연구 동기 및 목표

  • 현대의 이질적 네트워크에 통합된 컴퓨터, 장치, 인간 행위자를 보호하기 위한 고수준 설계 방법론의 부족을 해결하기 위해.
  • 기존 보안 프로토콜과 인간-컴퓨터 과정이 융합된 사이버-사회적 시스템의 현실 간 격차를 메우기 위해.
  • 복잡한 분산 절차에서 보안 성질에 대한 다이어그램적 및 논리적 추론을 지원하는 형식적 프레임워크를 개발하기 위해.
  • 이중 인증 및 장치 쌍화와 같은 실제 프로토콜을 인간, 장치, 채널 상호작용의 통합 모델 내에서 엄밀한 분석을 가능하게 하기 위해.

제안 방법

  • 이질적 시스템에서의 계산을 위한 형식적 모델로 액터-네트워크를 제안하며, 인간, 장치, 통신 채널을 모두 네트워크 노드의 일등 시민으로 간주한다.
  • 다이어그램적 추론과 형식적 추론을 융합한 논리 프레임워크인 절차 유도 논리(PDL)를 도입한다.
  • 프로토콜 흐름을 표현하고 지역적 제약 조건에서 보안 성질을 도출하기 위해 그래픽 템플릿과 논리적 주석의 조합을 사용한다.
  • PDL를 적용하여 두 가지 구체적 프로토콜을 분석한다: 이중 인증 체계와 다중 채널 장치 쌍화 절차.
  • 메시지 흐름을 모델링하고 불일치 또는 취약점을 탐지하기 위해 부분 순서를 가진 다중집합의 사건에 대한 시간적 및 인과적 추론을 활용한다.
  • 기존의 프로토콜 유도 논리(PDL) 개념을 활용하고, 보안 추론에 인간 및 사회적 구성 요소를 포함하도록 확장한다.

실험 결과

연구 질문

  • RQ1인간, 장치, 통신 채널을 통합하는 시스템에서 보안 프로토콜을 어떻게 형식적으로 모델링할 수 있는가?
  • RQ2하이브리드 네트워크 절차에서 구조와 구성 요소 기여도에 대해 추론할 수 있는 논리적 프레임워크는 무엇인가?
  • RQ3다이어그램적 추론과 논리적 추론을 효과적으로 융합하여 초기 단계의 프로토콜 설계 및 검증을 지원할 수 있는가?
  • RQ4다자간, 다중 채널 상호작용에서 정당성과 정확한 메시지 흐름과 같은 보안 성질을 어떻게 형식적으로 도출할 수 있는가?
  • RQ5형식적 논리가 개인의 인간 행동을 완전히 예측 가능하게 하지 않더라도, 사회적 상호작용을 어느 정도 모델링할 수 있는가?

주요 결과

  • 제안된 액터-네트워크 모델은 현대 보안 절차에서 계산적 요소와 사회적 요소 간의 상호작용을 성공적으로 포착한다.
  • 절차 유도 논리(PDL)는 이중 인증 및 장치 쌍화에서 메시지의 진위성과 참가자의 정당성과 같은 보안 성질의 형식적 검증을 가능하게 한다.
  • 주석이 추가된 다이어그램을 통해 초기 단계의 추론을 지원하여, 형식적 분석을 화이트보드 수준의 설계 논의에 통합할 수 있다.
  • 이중 인증과 다중 채널 쌍화의 분석은 장치와 채널의 지역적 제약 조건이 원하는 전역적 보안 결과를 보장할 수 있음을 보여준다.
  • 부분 순서를 가진 다중집합의 사건은 인과 경로가 모호하거나 구분이 어려운 경우에도 메시지 흐름에 대한 견고한 추론 기반을 제공한다.
  • 논문은 개인의 인간 행동은 여전히 예측 불가능하나, 계산 시스템과 융합된 사회적 네트워크에서의 집단적 행동은 효과적으로 모델링할 수 있다고 결론 내린다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.