Skip to main content
U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock ( ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Formal Verification of Bootstrapping Remote Secure Key Infrastructures (BRSKI) Protocol Using AVISPA

Published

Author(s)

Monika Singh, Mudumbai Ranganathan

Abstract

The last decade has seen significant growth in the number of IoT devices. These devices can connect to each other and networks. The process through which a new IoT device connects to the network and subsequently enables its services is called bootstrapping. A single entity connecting large numbers of new IoT devices to networks makes manual bootstrapping infeasible. It requires an automated system to enable a new device to be located and securely onboard the network. The Bootstrapping Remote Secure Key Infrastructure (BRSKI) protocol is one of the well-known protocols that provides a way for secure device onboarding. In this work, we present the first formal security analysis of the BRSKI protocol using a verification tool called AVISPA (Automated Validation of Internet Security Protocols and Applications). AVISPA provides a formal security validation of any network protocol by building and analyzing the formal security models of that protocol’s operations.
Citation
Technical Note (NIST TN) - 2123
Report Number
2123

Keywords

Authentication, AVISPA, Bootstrapping, HLPSL, SPAN, Formal Verification, X.509 certificates.
Created October 6, 2020, Updated October 7, 2020