E3C: A Tool for Evaluating Communication and Computation Costs in Authentication and Key Exchange Protocol
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "E3C: A Tool for Evaluating Communication and Computation Costs in Authentication and Key Exchange Protocol".
Elias: Calculating computational and communication costs for authentication and key exchange protocols is crucial for designing lightweight protocols suitable for resource-constrained environments like IoT systems, where minimizing computation pressure is essential.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So we're looking at this paper, "E3C: A Tool for Evaluating Communication and Computation Costs in Authentication and Key Exchange Protocol," and the title immediately tells us it's about a tool for figuring out how much processing and communication different authentication protocols require. It sounds like they’re tackling that tedious manual calculation issue head-on.
Elias: Indeed, Nadia, the authors are Yashar Salami and Vahid Khajehvand from Qazvin Branch at Islamic Azad University, and their focus on automating cost analysis for IoT systems is really interesting to me. It suggests they're targeting a very specific area where resource constraints are a major concern for lightweight protocols.
Priya: I think the implication here is that we can move past just looking at security proofs and start looking at the real-world operational expenses, like how much battery life or processing power a device will consume when running those protocols.
Nadia: Exactly, Priya; it’s about making sure we aren't just designing something secure on paper but something that actually runs efficiently on hardware, which is a huge practical consideration in the Internet of Things space.
Elias: I agree with Nadia; the core idea seems to be providing an automated way to compare protocols in terms of both communication and computation costs, which is a significant step up from what was available before.
The paper's summary: Nadia: So, the paper explains that they developed this E3C tool because manual calculation of computational and communication costs for authentication and key exchange protocols usually leads to human error when you need to compare several protocols side-by-side.
Elias: That’s right; the paper says that while tools like Avispa or Scyther can validate security properties, none of them calculate these exact costs, so manual work gets messy when you want to repeat a protocol multiple times for comparison.
Priya: From my angle, what I find important in their summary is that they are focusing on reducing those calculation errors and giving users a single chart where they can see the total cost for various protocols at once.
Nadia: That’s the main point—reducing manual errors and enabling easy, simultaneous comparison of these costs across different authentication methods.
Elias: The authors contribute by presenting this automated E3C tool, which uses a specific language called CAS+ to define the protocols, allowing users to customize the cost of functions used in those protocols.
Priya: So they’re not just calculating something; they’re letting you define the structure using CAS+ and then letting the tool do all the heavy lifting for both communication data sent and function execution time.
The paper's improvements: Nadia: I see that they are improving things by providing an automated way to calculate these costs, specifically using CAS+ language to define protocols, which makes it much easier for users to implement the actual protocol structure.
Elias: They also point out that E3C allows users to customize the cost of specific functions within those authentication and key exchange protocols, which gives a level of control over the variables they are measuring.
Priya: The improvement in terms of output is really significant because they let you automatically receive the results in the form of a chart, which lets you visualize how communication and computation costs stack up visually.
Nadia: So instead of just getting raw numbers, we get a graphical representation that shows the total cost for comparison purposes, which directly addresses that need for easier side-by-side analysis.
Elias: It sounds like the improvements center on accessibility through the CAS+ language definition and visualization through automatic charting to make comparing these protocols much more efficient than before.
Conclusion: Nadia: So, to wrap up, this paper introduces E3C as a tool that automates the calculation of communication and computational costs for authentication and key exchange protocols with high accuracy, which is a big help in minimizing human errors during protocol design.
Elias: And the main implication is that it gives researchers an efficient way to compare several different protocols simultaneously through a chart, which speeds up the comparison process significantly compared to doing it by hand.
Priya: It really highlights how crucial this cost-aware analysis is when we’re designing protocols for resource-constrained environments, because understanding those exact metrics directly impacts deployment feasibility.
Nadia: Right, Priya; it confirms that automating these complex calculations helps developers increase the readability of protocols and reduce those kinds of human errors we always worry about.
Elias: It's a useful piece of software that bridges the gap between formal protocol design and real-world performance metrics, which is what E3C delivers in this work.
Yashar Salami, Vahid Khajehvand
Department of Computer and Information Technology Engineering, Islamic Azad University
cs.CR
Submitted: 2022-12-06
Updated: 2022-12-06
Comments: 20 pages ,10 figures, 4 Table
Journal ref: Iran Journal of Computer Science 7, 325-335 (2024)
DOI: 10.1007/s42044-024-00176-x
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 72/100
The gist: Calculating computational and communication costs for authentication and key exchange protocols is crucial for designing lightweight protocols suitable for resource-constrained environments like IoT
Key concepts
- Computational Cost
- This cost measures the processing time required for cryptographic functions within a protocol. It is determined by considering the execution time of these functions during the protocol's operation. This metric is vital for resource-constrained systems like IoT devices where minimizing processing load is essential.
- Communication Cost
- This cost quantifies the amount of data exchanged between different parties during a key exchange or authentication process. It is calculated based on the total number of data units sent and received by each participant in the protocol, helping designers understand network overhead.
- CAS+
- CAS+ is a specific programming language used by users to implement their cryptographic protocols within the E3C tool. It provides a structured way for developers to define elements like roles, messages, knowledge, sessions (instances), and goals necessary for protocol modeling.
- E3C Architecture
- The E3C system is built on four main parts: coding (using CAS+), calculation (determining costs), comparison (using memory management for speed), and display. This structure allows users to implement a protocol, get accurate cost results, and visually compare multiple protocols simultaneously.
Terminology
Summary
Calculating computational and communication costs for authentication and key exchange protocols is crucial for designing lightweight protocols suitable for resource-constrained environments like IoT systems, where minimizing computation pressure is essential. This paper proposes E3C, an automated tool designed to calculate these costs with high accuracy, thereby reducing human error associated with manual calculations and enabling efficient comparison of various cryptographic protocols.
The gist: The E3C tool can calculate the processing and communication costs of authentication and key exchange protocols with 99.99% accuracy, comparing several protocols in terms of communication and processing costs.
Problem Statement
The primary motivation for E3C stems from the limitations of existing formal tools; while tools like Avispa, Scyther, and Proverif can validate security properties, none of them can calculate computational and communication costs. Manual calculation is prone to human error,
especially when researchers need to repeat this protocol several times to compare their protocol with other key exchange and authentication protocols.
Therefore, there is a critical need for an efficient tool that can calculate the computational and communication costs of authentication and key exchange protocols
automatically, allowing users to compare the cost of several protocols simultaneously in one chart.
E3C Architecture
The E3C architecture is structured around four core components: coding, calculation, comparison, and display. The coding component allows users to implement their protocol using a specific language called CAS+. The calculation component determines the costs based on the implemented code: Communication cost is calculated based on the number of data sent between the communication parties,
and The execution time of cryptographic functions is considered to calculate the Computation cost.
The comparison component uses memory management techniques to improve E3C performance, allowing users to compare different protocols with a single click.
Finally, the display component allows results to be presented graphically: This component allows users to display the results of calculations in the chart, single and total,
and This section shows the results in the form of a chart for the user.
Workflow
The E3C user workflow is summarized into several distinct steps. First, users must implement their protocol using CAS+. The paper provides an example structure for this language, showing how to define roles, messages, knowledge, sessions (instances), and goals. Second, users must Save the protocol with the suffix.CAS+, which ideally specifies the protocol.
Third, users can customize parameters by setting the protocol's symbols and arithmetic mean (ms).
Fourth, the user executes the tool; if there are no grammatical problems in the implementation, E3C displays results. Finally, users can utilize various sections of the graphical environment to compare protocols with each other
and view the total results for the user
in a chart.
Performance Analysis and Results
The tool's effectiveness is demonstrated by evaluating several classical and modern protocols against manual calculations. The paper examines protocols such as Wide Mouthed Frog, Needham Schroeder Public-key, Otway–Rees, SMAK-IOV, and LSKE. For instance, the manual calculation for the Needham Schroeder Protocol yielded a total cost of 23.1ms,
whereas E3C calculated it as 23.1 ms.
Similarly, for the LSKE protocol, manual calculation resulted in a computation cost of 19.870 ms
and a communication cost of 3, which E3C replicated exactly. The comparison between manual calculations and E3C results shows that the accuracy is consistently high: The results of manual calculations are the same as the results of manual calculations and E3C shown in Table 4,
confirming an accuracy close to 99.99%.
Conclusion
E3C is presented as a unique tool for evaluating these costs, supporting the CAS+ language for easier implementation. The evaluation confirms that E3C can calculate the processing and communication costs of authentication and key exchange protocols with 99.99% accuracy, and the calculation speed increases compared to the manual method.
The tool minimizes human error by automating complex calculations and provides a graphical interface for comparison, ultimately helping developers increase the readability of protocols and reduce human errors.
Future work planned includes adding capabilities to adjust the communication Channel Properties and detect Corruption in authentication and key exchange protocols.
References
[1] J. Kim and E. Park, “Understanding social resistance to determine the future of Internet of Things (IoT) services,” Behav. Inf. Technol., vol. 41, no. 3, pp. 547–557, 2022.
[2] A. D. Boursianis et al., “Internet of things (IoT) and agricultural unmanned aerial vehicles (UAVs) in smart farming: A comprehensive review,” Internet of Things, vol. 18, p. 100187, 2022.
[3] E. Khezri, E. Zeinali, and H.
Improvements for AI systems
Based on the provided scientific paper, here are specific improvements that can be made to AI systems by leveraging the findings of the E3C tool and its methodology:
-
Enhanced Protocol Selection for Resource-Constrained Environments:
-
Automated Lightweight Protocol Design and Optimization:
-
Accurate Cost-Aware System Deployment (Deployment Intelligence):
-
Human Error Mitigation in Cryptographic Implementation (Development Assistance):
Specific Improvements and Capabilities of the Improved AI System:
- AI-Driven Protocol Selection for Resource-Constrained Environments:
The system can ingest a list of potential authentication and key exchange protocols (like Wide Mouthed Frog, LSKE, or SMAK-IOV) and a set of hardware constraints (limited memory, low computation power). The AI would use the E3C tool's cost calculation capabilities to automatically rank these protocols based on their calculated communication and computational costs.
The improved system can then select the protocol that minimizes the total cost for a specific deployment scenario, ensuring optimal performance for IoT devices or other resource-limited platforms.
- Automated Lightweight Protocol Design and Optimization:
The AI can be tasked with designing or modifying existing protocols using the CAS+ language, guided by cost constraints. The E3C tool allows users to define protocol symbols and arithmetic means, which suggests the AI could iteratively adjust these parameters within the CAS+ framework to achieve a target computational cost while maintaining required security properties.
The improved system can automatically generate optimized versions of protocols that meet specific performance benchmarks without requiring manual, error-prone recalculations.
- Accurate Cost-Aware System Deployment (Deployment Intelligence):
When deploying AI agents or IoT devices, the system could use E3C to predict the exact energy and processing expenditure associated with different communication patterns and key exchange methods. This allows for cost-aware
deployment decisions, where the AI chooses not only based on security but also on operational expenditure (OPEX) related to computation and communication bandwidth.
The improved system can make real-time decisions about which protocol to use during a session, dynamically adjusting parameters based on network conditions or device load to stay within predetermined cost envelopes.
- Human Error Mitigation in Cryptographic Implementation (Development Assistance):
The AI can serve as a rigorous automated reviewer for code written in the CAS+ language before it is used for implementation. By feeding the protocol definition into E3C, the system can instantly check if the defined structure aligns with expected computational complexity models and flag potential logical inconsistencies or excessive operations that might lead to performance bottlenecks.
The improved system can provide immediate feedback on protocol design flaws related to cost efficiency, significantly reducing the risk of performance-related bugs during implementation phases.
Abstract
Today, with the development of blockchain and Internet of Things technologies, we need authentication protocols and key exchanges to communicate with these different technologies. Symmetric and asymmetric encryption methods are used to design authentication and key exchange protocols, each of which has different computation costs. In the Internet of Things systems, due to the limited memory and computation power, researchers are looking the lightweight design protocols so that the pressure caused by the computation of protocols can be minimized. Calculating protocols' computational and communication costs was done manually until now, which was associated with human error. In this paper, we proposed an E3C tool that can calculate the computation and communication costs of the authentication and key exchange protocols. E3C provides the ability to compare several protocols in terms of communication and processing costs and present them in separate charts. Comparing the processing and communication costs of classical and modern protocols manually and with the E3C indicate that the E3C can calculate the processing and communication costs of authentication and key exchange protocols with 99.99% accuracy.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs