Logo del repository
  1. Home
 
Opzioni

Automated symbolic verification of Telegram’s MTProto 2.0

Miculan M.
•
Vitacolonna N.
2021
  • conference object

Abstract
MTProto 2.0 is a suite of cryptographic protocols for instant messaging at the core of the popular Telegram messenger application. In this paper we analyse MTProto 2.0 using the symbolic verifier ProVerif. We provide fully automated proofs of the soundness of MTProto 2.0’s authentication, normal chat, end-to-end encrypted chat, and rekeying mechanisms with respect to several security properties, including authentication, integrity, secrecy and perfect forward secrecy; at the same time, we discover that the rekeying protocol is vulnerable to an unknown key-share (UKS) attack. We proceed in an incremental way: each protocol is examined in isolation, relying only on the guarantees provided by the previous ones and the robustness of the basic cryptographic primitives. Our research proves the formal correctness of MTProto 2.0 w.r.t. most relevant security properties, and it can serve as a reference for implementation and analysis of clients and servers.
DOI
10.5220/0010549601850197
WOS
WOS:000720102500015
Archivio
http://hdl.handle.net/11390/1210973
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-85111859162
https://ricerca.unityfvg.it/handle/11390/1210973
Diritti
metadata only access
Soggetti
  • Formal Method

  • Practical Verificatio...

  • Privacy

  • Security Protocol

  • Specification

  • Verification and Synt...

google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback