next up previous
Next: Properties (Goals) Up: D6.1 - List of Previous: Introduction

Coverage and Relevance Assessment

Having taken into consideration the feedback of IETF representatives, it is possible to assess the coverage of the proposed set of protocols by examining the individual charters of the working groups of the IETF and by reviewing the Internet Architecture Board documents on the Security of the Internet, and the Requests for Comments devoted completely to security, namely [32,159,33,160,174].

Our set of candidate protocols includes almost all protocols recommended by the Internet Architecture Board (IAB) during a meeting on 3-5 March 1997 in Murray Hill, NJ (reported in [32]). The IAB recommendations were:

The list is five years old (it was published as RFC in April 1998); an update would be of interest. For instance, perhaps today Security/Multipart would not be seen as ``core'' security mechanism, but rather CMS (Cryptographic Message Syntax, see [85,86,196]).

We will not model any of the protocols considered as ``not useful'' or unacceptable in [32], in particular any protocol where plaintext passwords are sent over unencrypted channels.

For an overview of the security mechanisms for the Internet see [33]. Our protocols also cover most of them. While there is partial overlap between this list and the previous one from [32], we include both lists for easy reference to the sources.

The mechanisms described in [33] are:

Our protocols also cover most of the recommended authentication mechanisms for the Internet described in [159]:

Our list of protocols does not include two groups of insecure authentication mechanisms for the Internet discussed but not recommended in [159]:

The other two RFCs solely dedicated to security ([160,174]) do not contain lists of protocols or mechanisms, but discuss the types of security properties that an Internet may want to have and the attacks that it may be subject to. We have gone through the two documents with great care and incorporated all relevant security properties into our list.


next up previous
Next: Properties (Goals) Up: D6.1 - List of Previous: Introduction
AVISPA Project -- Deliverable 6.1 'List of Selected Problems'