Provably Insecure Mutual Authentication Protocols: The Two-Party Symmetric-Encryption Case

In practice, users will rely on a wide variety of communication protocols to conduct their work over the Internet. This paper discusses the security rami cations of using multiple authentication protocols. We demonstrate multi-protocol attacks and how they can be realized to defeat otherwise secure authentication protocols. We highlight this discussion with examples of attacks on a proposed symmetric key-based authentication protocols. We present a model of communication that re ects the existence of this type of attack, and demonstrate that a class of authentication protocols can never be secure in the presence of this type of attack.