Rational Dolev--Yao Attackers: Decidable Incentive-Aware Verification of Security Protocols in Strategic Logic

📅 2026-08-24
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
该研究通过引入理性Dolev-Yao攻击者模型,使用加权ATL逻辑验证协议的安全性,解决传统模型无法考虑攻击成本和收益的问题。
📝 Abstract
Symbolic protocol verification models the network attacker as a Dolev--Yao (DY) intruder, which does everything its knowledge permits, whether or not it serves any purpose; real adversaries instead maximise utility, attacking only when the payoff is positive. We introduce a rational Dolev--Yao attacker, a DY intruder whose actions carry costs and whose security-violating goals carry rewards, and call a protocol rationally secure when no intruder strategy achieves a violation with strictly positive utility, expressed in a weighted fragment of ATL (WATL). We prove this decidable for a bounded rational DY intruder over a finite cost-annotated concurrent game structure, characterise its complexity, and show it strictly refines DY security: some protocols are DY-insecure yet rationally secure, separated by a computable threshold. We illustrate the framework on two contrasting use-cases: an authenticated payment under session uncertainty, where a rational intruder must strategise across indistinguishable sessions and its imperfect information strictly raises the attack cost a designer must price against; and ThreeBallot, a cryptography-free scheme where we pinpoint the bribe-to-benefit ratio below which no rational coercer attacks.
Problem

Research questions and friction points this paper is trying to address.

Rational Dolev--Yao attacker
Incentive-aware verification
Security protocols
Strategic logic
Utility
Innovation

Methods, ideas, or system contributions that make the work stand out.

rational Dolev--Yao attacker
incentive-aware verification
WATL
bounded rational DY intruder
cost-annotated concurrent game structure