SecureCommunicationUsingRemoteProcedureCallsAndrewD.BirrellFebruary13,19842:56pm{Copyrightnoticegoeshere}Abstract:Researchonencryption-basedsecurecommunicationprotocolshasreachedastagewhereitisfeasibletoconstructend-to-endsecureprotocols.Thispaperdescribesthedesignofsuchaprotocol,builtaspartofaremoteprocedurecallpackage.Thepaperdescribesthesecurityabstractionpresentedtousersofthepackage,theauthenticationmechanisms,andtheprotocolforencryptingandverifyingremotecalls.CRCategoriesandSubjectDescriptors:ClassNo[MajorClassification]:ClassificationTopicDescriptors,Descriptors,...ComputingReviewscategoriesgohere;GeneralTerms:keywords,keywordsTheauthor'spresentaddressis:DigitalEquipmentCorporation,ComputerSystemsResearchLaboratory,130Lytton,PaloAlto,CA94301.TheworkdescribedherewasperformedwhileemployedbytheXeroxCorporation.XEROXXeroxCorporationPaloAltoResearchCenter3333CoyoteHillRoadPaloAlto,California94304PRELIMINARYDonotdistributewithouttheauthor'spermissionpîïT†î ! î9î'}îïOîuqîïI€îƒîÉrîïCýîÿîöî Úî oîïîÇî%— î,Òî.úsîï%«î$tî ¤ï%«î�sîïôî~î Uî³îStî´ïôî•î'M î0/î7Xîï¿îû î5îfî¨î]î(î!öî'ôî+Fî/>î6pî:0îï‹î&î ûî³î¹îDî† uîï …tî&Âï žî+ î&Âï jî*î--î3Îî&Âï 5î*`î/iî1óî&Âïî*î-� î4<vîï˜ îxî¿îÏîi î&®î/ªî4Dîïd Æ « åH«c?SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS11.IntroductionManycomputingenvironmentsnowexistwherefrequentandsubstantialpartsoftheactivitiesinvolvecommunicationamongstcomputerslinkedbyopennetworks.Ausermaywellspendmostofhistimeatapersonalcomputer,andusenetworksfortransferringdatatoandfromotherpersonalcomputers,orsharedservercomputerssuchasprinters,fileserversandmailservers.Mostofthenetworks(andinternetworks)usedfortheseactivitiesareopeninthesensethattheyarereadilyvulnerabletoeavesdroppingandinterferencefromunauthorizedintruders.Suchanarchitecturepresentssecurityproblemsmuchdifferentfromtheonestraditionallyfacedinmonolithictimesharingsystems.Inparticular,itisclearthatsecuritymustbebasedontheuseofencryptioninthecommunicationprotocols.Fundamentally,encryptionpermitstheestablishmentofadatachannelthatislessopenthantheunderlyinginternetwork,byarrangingthatonlyauthorizedpartiescancreate,inspectand/ormodifysomeorallofthedata.Establishing,usingandmaintainingsuchasecuredatachannelrequirestheresolutionofmultipleproblems.First,itisnecessarytoidentifytheauthorizedparties(traditionallycalledprincipals).Second,itisnecessarytoconvinceeachprincipalthattheothersareindeedwhotheyclaimtobe.(Thisstepistraditionallytermedauthentication.)Third,itisnecessarytotransfertheactualdatainamannerthatisnotvulnerabletothevariousthreats.Thesecondandthirdoftheseareinevitablyinterdependent,sincearecipientmayrequireconvincingthateachparticulardatumdidindeedcomefromtheassertedsender.Thereareseveraldiscussionsinthepublicliteratureaboutdesigningcommunicationprotocolstoachievevariousformsandlevelsofsecurity.Muchofthepublishedmaterialisconcernedwithparticularaspectsoftheoverallproblem,especiallythedesignandimprovementofauthenticationprotocols[1,5,10].Thereislessmaterialavailabledescribinghowtoconstructacompletesecurecommunicationprotocol.ArecentreportbyVoydockandKent[11]givesathoroughdescriptionofonesuchdesign,includingsubstantialdescriptionofthesupportingargumentsfortheirdesign.Therearedisappointinglyfewrealimplementationsofsecureprotocols.Thepurposeofthispaperistodescribetheconstructionofsuchaprotocol.Itispossibletoincludesecurecommunicationatvariouslevelsinthecommunicationprotocolhierarchy.Atthephysicallayer,securitycanbeachievedbyvariousnon-cryptographictechniquesthatpreventtamperingwiththecommunicationmediumitself.Atthenetworklayer,itispossibletoencryptalltrafficoneachnetworkusingacodewhosekeyissharedamongallnodesdirectlyconnectedtothatnetwork.Thisistermedlinkencryption;itprotectsagainstintrudersfromoutsidethecommunitythatsharesthatnetwork,butdoesnotdistinguishprincipalswithinthatcommunity.Whenmultiplenetworksareinvolvedinacommunicationpath,linkencryptionallowsintrusionbymembersofthetrustedcommunityofeverynetworktraversedbythepath.Thelowestlayeratwhichwecanprovideanend-to-endguaranteeistheinternetworklayer,whereweintroducedirectnode-to-nodeaddressingofpackets.Butinmanycommunicationarchitectures(includingours)itisnotuntilthetransportlayerthatend-to-endsecurityisfeasible.Thetransportlayeristhelowestlevelatwhichenoughstateinformationiskepttoestablishtheauthenticityofincomingdatainsuccessivepacketsofaninteraction.Itisthetransportlayerwherewearefirstconcernedwiththewî ÿï]7xî Æï]7î ï]7wî&ï]7xî$ï]7 wîKï]7xîjï]7wî´ï]7xî ½ï]7wî%@ï]7xî&ï]7wî-ï]7xî.ï]7tî;éï]7yîïUDî� wîÂïQùîÃî © îGîVî‘î ´î&Oî) î/ìî3_î5#î7Ž îïOÄîÙ î‘îîÅîî!î$}î+@î,Óî/Òî2Ûî5Ïî9×îïM�î¦îÅî×î\î rîãîRîöîXî î"J î) î,‘î.,î0Ðî4$î7¯îïK[ îîðî gî†îGîŠîJî"Êî%Fî)éî,²î/Þî5nî9 î:ÔîïI'îî _ îŸîîkî î!ëzî$hïI'î%ïI'wî'ÏïI'î)¦î,.î/öî2íî6&î8¢îïFò î÷îØ î"î îÔî m zî(ýïFòî)`ïFòwî.$ïFòî/éïFòî3�î5² îïD¾î8î /îîÍîRî™îØî!è î)~î-î.– î5[î8`îïB‰îVîb î-îÁîiîøîîWî!üî$*î(Iî*Œî-)î/Ûî1Ñ î8éî:Ôîï@U î Ê îÆ î¼ î!­î&¹î)/ î1æî3µî4öî8îï>!î÷îŠîHî ãî1î¸ îÑ î kî"Žî(ßî+Öî/ î6î:¨îï;ìînî )î ãî³îXî/î2îýîoî"u î*—î.Sî1 î8Åî< îï9¸îRîoî ©îî† î îÛî"mî)‚î-8î.§î0+î6Vî8îï7ƒî¢ î ³îf îØzîï7ƒîÂï7ƒwî ®ï7ƒî!'ï7ƒî# î(zî*î+¿î2î4î:îï5Oîî ,î ÖîDîãîµîî_î"_î$Xî'ºî+™î.Èî0~ î8€zîï3 wîUï3î¬ï3î =î~îÜîOîjî î2î ™î$¤î'°î)fî*—î/©î2î3óî6o îï0æî¥îûî¹î ýîËîSîî_îî Žî"Ø î)#î2úî6bî7‚îï.±îîÍ î½îŒî½ îòîBî!¸î&?î)èî-Oî/¯î4æîÂï,}îÓî 5î Õ îêî§îî_ î#Vî'Gî- î7Aîï*Hî¼î³î ˆî€îEîîâîîî!þî#Äî&1î,•î1úî3sî:îï( îNî î ÞîVîóîç î 3î"ªî'î)à î2jî4; îï%àîî ýî%î¶îrîïîÐ î&�î)¹î+�î1œî2ìî8úîï#« î Èî:îÛîîKî[î"6î%î(•î+Uî.Ûî0î6! îï!wîÐî“îÛî ™îÄ îª î Óî"£î% î,î2Ûî5/î8�îïBî îdîî»îxîãî!£î%ã î,Àî/Ÿî4éî6©î9Rîïîlîî~î Þ î¬îeî–îÀîÂïÙîCî¸î î ºî£îæ î¢î!Dî&î)éî+ î. î7Åîï¥ îî î vîÎî˜î¹îOîKî$î& î*àî6W îïpîØîâîxî�î îÂî#:î'…î)Šî+óî1Tî5î6|î7ñîï<îÌîßîìî î:î‰îþîÅî î pî$»î'nî(÷î-yî2î4*î8>îïîsîî ÎîßîèîCzîåïîHïwî¤ï î$[î% î*¼î/Hî5î8jîïÓîbî ¢î rî—îhîî�îÏî!G î(: î.‡î2Îî5ž îï Ÿîî ™îyîÏîmîîK î$î'„î*T î12î5cî;8îï jîîùî îCî§zî‡ï jî!ï jwî,ï jî!ªî'¸î)Úî,`î0¯î3®î8 î;›îï 6îî=îÌî ÛîÏ îÚî)î˜î û î)î,Üî0øî3#î9Qîï î{ î;îñî¥îCîíî´ î(d î0f î6ðî:uî;ÈîïÍî�îìîdîYîØî¾ îÝî! î"�î(›î+‹î1€î4ÿî6ƒî8úîï˜îqî4î lî€îÜ î�î'îlî Eî& î(” î0@î2#î8Vî;…îïd îtî [î î îÚîYîÌî4î"î%‡î)§î+Öî.1î1î7±î:Ôÿ l « èH«c<2SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLSrelationshipbetweensuccessivepackets.Hereweintroducecodewhichhandlespacketsequencing,detectsmissingorrepeatedpackets,andretransmitstorecoverfromlostormalformedpackets.Thesemechanismsarejustwhatisneedtoimplementasecureprotocol,andsowehavechosentointroducesecurecommunicationasanaspectofthetransportlayerprotocol.Onecouldalsointroducesecurityfacilitiesathigherlevels.However,doingsowouldreproducemanyofthemechanismsalreadyextantinthetransportlayer.Thesemechanismshavealwaysbeendifficulttodesignandimplement,andoftensignificantlyreduceefficiency.Implementingthemtwiceseemsundesirable.Itwouldalsoreducetheutilityofthesecureprotocol,sincetheeasiestwaytocommunicatewouldlikelybebyusingthetransportlayerdirectly.Thisisparticularlytrueofremoteprocedurecalls,whereamajorpurposeistosimplifythetaskofcommunicating,byprovidingasinglesimpleandwidelysharedmechanism:procedurecalls.Ifsecurityweresomethingthatrequiredextraprogrammingbeyondtheprocedureinvokationitself,thenitwouldintrudeontheaimofeasycommunication.Largepartsofoursecuritydesignarederivedfrompreviouswork.Amoderateunderstandingofpreviousworkisneededforproperappreciationoftheremainderofthispaper;thereportbyVoydockandKent[11,12]isagoodintroduction.Asdiscussedinsection3,weusethefederaldataencryptionstandard(DES)forourencryption[4].Thischoiceisdictatedlargelybytheavailabilityofveryfast(andcheap)hardwareforDES.Hence,ourschemesarebasedontheuseofprivatekeys(insteadofpublickeys[8]).Forourpurposesitwouldbeimpracticabletohaveeachpairofprincipalsthatwanttocommunicateshareaprivatekey,soourschemeisbasedontheuseofanauthenticationservice(alsoknownasakeydistributioncenter).Thuseachprincipalhasasingleprivatekeyknownonlytotheprincipalandtheauthenticationservice.Whentwoprincipalswishtocommunicate,theynegotiatewiththeauthenticationservicetoobtainasharedconversationkey.Thisconversationkeyisusedtoencryptsubequentcommunicationbetweenthetwoprincipals.Thedesignpresentedherearoseaspartofaprojecttoimplementremoteprocedurecalls(RPC)ontheXeroxresearchinternetwork.TheoveralldesignofthisRPCpackagehasbeenreportedinanearlierpaper[3].PriortotheconstructionofthisRPCpackage,therewerenoencryptionbasedprotocolsintheinternetwork.Previousprotocolstransmittedpasswordsascleartextwheneveranyauthenticationwasdesired.PartofthedesignofthisRPCpackageincludedanewtransportlayerprotocol,andthisseemedlikeanidealopportunitytoincludesecurityfeaturesatthecorrectlevelintheprotocolhierarchy.AnadditionalfactorthatenabledtheintroductionofasecureprotocolwasthatmostsoftwareusingtheresearchinternetworkhadrecentlyconvertedtousingGrapevine[2]astheprimaryauthorityfornamingandauthenticatingindividualsandservices.ThisallowedustoenvisageusingGrapevineasthemediatorinthenegotiationtoestablishtheauthenticityoftheprincipalsinvolvedinsecurecommunication.2.TheSecurityAbstractionOfferedtoClientsClientsofourRPCpackageinterfacetoitssecurityfacilitiesbydealinginconversations.Atîï\wî Åï\xî Œï\î Eï\wîíï\xîêï\ wîï\xî0ï\wî zï\xî!ƒï\wî&ï\xî&×ï\wî-Îï\xî.Ìï\wîïT' îƒî õ îeî'î�îÈî$öî(@î,Qî1`î5¾ îïQóîÊî ôî îîÀî.î î!cî#Hî(\î+úî.Æî0Àî7üîïO¾î î Çî"îÊî/î¡îî»î!§î"Øî'î,æî/¥î1pî3žî6ìî;…îïMŠî+î e îîÆî¶îÚî“îóî%Ðî)7îÂïKUîµî pî ,îFîL îŸî'î"fî&ëî-î0ßî2“î6°îïI îÆîzîÔ î†îTîsîîvî"Nî&‡î*„ î25î5wî9ÖîïFìîeîAî ½î¡ î îðî° î$‰î)2 î0œ î9ªîïD·î²îÑ îGîÜî(îî«î (î$Hî&î(œî,óî2×î6gî8äîïBƒîáî˜ î îLîî îîÄî-î%î(ƒî.fî1‰î2ý î:Oîï@OîîîËî ƒîîlîËîöî mî"î#òî)sî,î/î1 î;8îï>î+îAî îhî î[î­ î"´î)"î,äî.Rî3Tî6�îï;æîâî…î î±î®î!î"· î)™î-aî0šî2î6Eî;-îï9±î`îîÏî Ó îÂï7|î±î î Ûîjî„îØî/î(î"”î('î,ˆî.î40 îï5HîÌînî þî |îXî¨î7 î "î!îî$`î+ î,Öî/‹î4�î7î;8îï3îÀîpî éîGî¬îÏî: îáî ëî&îî(•î-+î.±î0Òî3@î5™î:.îï0ß îæî �{î ï0ßî ãï0ßwîUï0ßî^ï0ßî§î= î#îî"6î&†î'ýî-Aî1Çî3Îî68 îï.«î²î¹îGî pîÚîÛxîï.«îöï.«wîNï.«îŸï.«î@î!Ãî'î)jî-Dî/Bî1šî4zî5¹ï.«î6iï.«î:#wîï,vîiî^î Õî+îôîÛî£î¦î 8î$£î&Ð î/‹î1vî4øî8fî;zîï*B î^î >î ­în îôî¥îáî �î#�î%fî(î,ôî.rî2fî4î6ðî9xî;Czîï( î wî ƒï( îñîžîszîÅï( îŒï( îx î"Âwî&Fï( î&¿ï( î(nî,î/lî5Zî7÷î9Hîï%Ùî¬îPî äî îÊî8î îÓîA î'Iî,Èî0îî3© î:îï#¤î» î “î °î¤îÌî8 î"=î&Ðî(‹î,Üî.zî2…ï#¤î3ï#¤ î:PwîîÖî#8î%xî'¸ïî(Œïwî*–ïî/ëî2sî5ãî;…îïÒîùîEî /î î�îTî¼ î’îTxî þïÒî!ÒïÒwî#ÑïÒî)tî-î0`î2o î9Rîïžîûî°î  îî¾î¸ î%ÿî,ˆî.>î1—î4Vî:’îïi î î Êî”î•îaîÓî4îxî!´ïiî"ˆïiwî$’ïiî)æî/Ÿî0Üî3Üî9Ìîï5îØî¡î TîOî îî{ î î!Øî&Éî+ñî1/î2Ùî5Jî9íîïîÅî;î À îÝîG îÔî×î ¼î%ÿî(u î0eî24î3uî7ÅîïÌî¿î¡î î�îZîÍîD î"qî%<î*‡î0ñî2²î6oîï ˜îôî›îóî "îî9î&îÖ î#¼ î*»î-kî3Cî6Vî;dîï cîÄî]î îôî·î,îîÖî J î'‡î)Jî.úî1o î9î:Ôîï / îLî åî “îÍ yîï°î�îfî Ó î1î0îéwîÂïdî—î }xî 5ïdî ïdwî-ïdî�îpîLîTî#— î)(î+Qî0Rzî2-ïdî2Èïd wî9ìïdî;§ïd s « H«bSECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS3conversationrepresentsacommunicatingpairofsecurityprincipals;duringsecurecommunication,oneoftheseprincipalsisanimplementorofaremoteprocedure,theotherisacalleronthatprocedure.AclientcancreateaconversationbypresentingtheRPCruntimesystemwithhisnameandprivatekey,andthenameoftheotherprincipal.Subsequently,ifthatconversationisanargumentofaremoteprocedurecall,theRPCruntimesystemensuresthatthecallisperformedsecurelyusingaconversationkeyknownonlytothosetwoprincipals.Weguaranteetothecallerandcalleethattheyarethetwoprincipalsnominatedwhentheconversationwascreated.(Moreprecisely,weguaranteethatthecallerandcalleeareeachtrustedbyoneofthoseprincipals,totheextentofhavingbeentoldtheconversationkeybyoneofthem.)Whenaserverisinvokedforanincomingcallwithaconversationasargument,theservermayasktheRPCruntimesystemforthenameoftheotherprincipalintheconversation.Thus,ourclientsneverdealexplicitlywithencryption,buttheygettheappropriateguarantees.Creatingaconversationinvolvesaninteractionbetweentheprincipalwhowishestocreateitandtheauthenticationservice(asdescribedinsection4).Usingaconversationtomakearemotecall(describedinsection5)involvesonlythetwoprincipals-theauthenticationserviceisnotconcernedwiththis.Forexample,ifprincipalAwishestocommunicatesecurelywithprincipalB,thenA'sprogramwouldincludeacallontheRPCruntimesystemoftheform:conv_RPC.CreateConv[from:nameOfA,to:nameOfB,key:privateKeyOfA]PrincipalAcouldthenmakeremotecallstoaprocedureP.QimplementedbyBsuchas:x_P.Q[thisConv:conv,arg:y]InsidetheimplementationofP.Q,principalBcouldfindtheidentityofhiscallerbyacallontheRPCruntimesystemoftheform:caller_RPC.GetCaller[thisConv];Thisconceptofconversationsisorthogonaltotheotherabstractionsinvolvedinacall.Multipleprocessescanparticipateinasingleconversation;theremaybemultiplesimultaneouscallsinaconversation;callscanbemadethroughmultipleremoteinterfacesbutstillbepartofthesameconversation.Callsmaybemadeineitherdirectioninaconversation,independentofwhichprincipalisthecallerandwhichisthecallee.Indeed,itwouldbeconsistentformanymachines(withthesametwoprincipals)toparticipateinasingleconversation,althoughwehavenotimplementedthis.Notethatwerestrictasecureconversationtoapairofprincipals.Wedonotdirectlysupportmulti-partyconversations(althoughtheymaybeemulatedbypairwisetwo-partyconversations).Nordowesupportthirdpartyoperations.Forexample,ifauserAcallsaserverBtoperformsomeoperation,theserverBcannotcommunicatesecurelywithathirdprincipalC(onathirdmachine)toperformsomeactiononbehalfofAmerelybyprovidingtheauthenticationinformationthatBobtainedfromA.Tosupportsuchinteraction,itwouldbenecessaryforAtoestablishaconversationbetweenhimselfandC,thengiveBenoughinformation(particularly,theauthenticatorandconversationkey)toallowBtoparticipateintheconversation.Suchinteractionscanbemadesecurely,andarenotruledoutbyourpackage,butweprovidelittleaidforthem.Whenbuildingasecuresystemofanysort,itisimportanttobeclearaboutthethreatsthatarewî ÿï\ xî Æï\ î ï\ wî&ï\ xî$ï\ wîKï\ xîjï\ wî´ï\ xî ½ï\ wî%@ï\ xî&ï\ wî-ï\ xî.ï\ tî;éï\ wîïT0 îÿ î‡î· îeîCîî# î*rî.éî3( îïQüîèîÜî¡ î(îÐîü î\îQî¶î#™ î*°î-Kî1&î2Íî43î8#î:eîïOÇ îgîøî ½îLîSî� î~î~ î%0xî'”ïOÇî(hïOÇwî*cïOÇî/žî4î7=î9tîïM“îîîÁî åî Óîiî^îNîäî¹ î#È î,Öî.mî1r î9¡î;CîïK^îTî6î ‰îYîîxîšïK^înïK^wîŽïK^î"ïî'“î,¦î/�î2&î4Úî6oîïI*î`î î Y îeî î¥îÒî“î"Eî% î,Pî.íî5Kî7 î9îïFõîÔîÇî ±î ÞîNîÊî’ îúî!ñî%Ãî(? î0Tî3î8ûîïDÁ îî>î�îeîÌî‡îEî"î }î#´î(Yî*\î-î.Îî2t î9î:ÔîïBŒî(îæî eî Æî£î îî�î�î"Mî$ î(ñî- î.;î2Lî3¼î9î;Cîï@Xîî¯î Øî  îîÓîcîÐî#ëî&ýî)txî+áï@Xî,µï@Xwî.ºï@Xî3ÿî8‰î:Ôîï>$îîîÇî µîËîÉîx î ëî%î'ëî,î0™î3á î:îï;ï î1î ¯î ¼îî_ î¼ î bî%ùî' î/î4kî6Y îï9»îoîÏî —î›îöî¤î§îþî¶î! î*î.•î0½î6èî8–îï7†îùî2î“ îÃî©î•îöîÔî— î&rî(Wî-+î/î4Ÿî7ðî:‡îï5R îLîIî © î¡î'î“îî!¡î$¼îÂï3îkî :î ˜|î]ï3wîÆï3îîÊ î";î'†î*ž|î0cï3wî1Uï3î20tî5Sï3wî6Fï3î7¤îï0éî/î î 8î ÃîÉxî(ï0éîüï0éwîóï0éî+î¦î_î!¾tîï.´î ºrî Gï.´î ï.´tî –ï.´î ùï.´îÚî ¾î"åî)Éî,ã wîï,tîÒï,wîIï,î î:îïî–î¥îTî}tî#ï,î#èï,wî%ãï, î.5tî00ï,wî1§ï,î4Ùtîkï*Jîªrî7ï*Jîðï*Jtîï*Jî–ï*Jî î$î'wîï(î.î™ î‚tîFï(î.ï(wî¥ï(îŒï(tî^ï(wîàï(î ¶î#°î&î+0î,ôî/2î2òî4øî6-î8Ãî:Ôxîï%áwîËï%áîî ~î7î–tî¸ï#¬îÄrîPï#¬îï#¬tîŸï#¬îï#¬wîÂï!wîËî Ñî z îæîA î î½î! î$š î, î1“î30î4Iî7ŽîïCî îÎ î¶î‡îÓîá î î#Èî&ïî)î.ž î7î:9î< îï î 3î aî îî÷îMîåî$ª î*òî-’î0Pî2_î5aî78î9¶îïÚ î—î êîÏî¡îBîÑîŸîGî Öî!á î* î1ãî3}î7lîï¥îƒîúîÆî ”î¹î<î³î“îªîî"]î$e î*Òî-'î1î7(î:Ôîïqîzî# î åî� îRîýî#î î$Yî*î,7î/zî1ì î::îÂï<îAî î GîáîîU îVî zî >ï<î ïï<wî#ï<î$Ô î, î.žî0­î3*î8'îï î î†î¦î î�îjî#Rî%9î*†î0¥î:MîïÓîî\î î þî© î`î"î! î"‚î#Â|î&ÒïÓwî(UïÓî+{î,»|î0ßïÓwî2lïÓî42î9 îï Ÿ îŒîôtî ï Ÿwî‹ï Ÿî î�î ãî$î%:î(¬|î.|ï Ÿwî0ï Ÿî2�î3Äî75îï jîÂî-î Óîþîîdtî0ï jwîºï jî^îmî%Àî(2 î1> î8Ûtî;¼ï jwîï 6î›tîìï 6wî ßï 6î î $îî5 îRî’î!ªî#„î)‚tî+©ï 6wî- ï 6î.¢î4'î5: îïîÖî tî9ïwî6ïîzîtî[ïwî9ïî‰ î&z î.üî1 î:|îïÍ î,î mî Ntî*ïÍwîÔïÍîµ î­îŽî î)Zî- î4’î7Pî9sîï™î¦î]î ±î &îÅî:î6îÁî[îÜî"î'î*?î,“î.ÐîÂïdîÕî Jî nî£îîÍîiîsîÄî *î&‡î(0î*î-hî1Eî3Ÿî8î:àÿ � « ÿH«b%¦4SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLSbeingcountered.Weguaranteetothecallerthathiscallwillbeperformedonlybyacalleewhosenamethecallerhasnominated.Wewilltellthecalleethetruenameofthecaller.Callscannotbeobservedintransit,totheextentthatanintrudercannotdeterminewhichprocedureisbeingcalled,noranyinformationabouttheargumentsorresults(excepttheirlength),Callsandresultscannotbemodifiedbyanintruderwhileintransit.Anintrudercannotcauseacalltobeinvokedmorethanonce.Wedonotattemptanyprotectionagainsttrafficanalysisoragainstdenialofservice(althoughclearlyacallerwillnoticeifhisremotecalldoesnotcompletebecauseofadenialofserviceattack).Itisalsoimportanttobeawarethattheseguaranteesarenotabsolute.Thebestthatcanbeofferedisthatwemakeitprohibitivelyexpensiveforanintrudertoviolatetheseguarantees.Theaimistomakethatexpensegreaterthanthevaluetotheintruder.Thecommunicatingprincipalsshouldtrustthesesecurityguaranteesonlytotheextentthattheytrusttheauthenticationservice,theencryptionalgorithm,andeachother.3.EncryptionAlgorithmsAsmentionedinsection1,weusethefederaldataencryptionstandard(DES)forourencryption.WemadethischoiceprimarilybecauseDESisavailableincheap,fasthardware(asfastas14megabitspersecond).TherehasbeensomecontroversyoverthecryptographicstrengthsandweaknessesofDES,butthesearenotimportanttoourdesign.Thedesignwouldbeunaffectedbyachoiceofanyotherprivatekeyencryptionalgorithm.Ourdetailedpacketformatsallowformultipleencryptionalgorithms,andforkeylengthsupto128bits.Useofapublickeysystem[8]wouldhavealargeimpactontheauthenticationprotocol.Basically,DESmaps64-bitblocksofplain-textinto64-bitblocksofcipher-text.Thatbasicmappinghidesthedata,butdoesnothidepatterns(suchasrepeatedblocksofzeros)anddoesnotdetectmodifications.Thecipherblockchaining,orCBC,modeofDES[6]hidesthepatterns,butstilldoesnotguaranteetodetectmodifications.WeusetheCBCmodewiththeadditionofa64-bitchecksumencryptedattheendofthepacket.Thischecksumisformedbyaccumulatingthe64-bitexclusive-oroftheplaintextblocks(thisisperformedbyhardwareinparallelwiththeencryption).Thistechniquereducestheprobabilityofmostundetectedmodificationsto2-64.Thisassertionisbasedontheobservationthatfromthepointofviewofanintruderwhodoesnotknowtheconversationkey,modifyingablockofciphertextproducesanunpredictablemodificationtotwoblocksofplaintextwhendecrypted.Itisfairlysimpletoshowthatarandommodificationto64-bitsofplain-texthasprobability1-2-64ofchangingtheresultingchecksum.AnalternativemodificationtoCBCmodehasbeenproposedbyEhrsam,etal[7],whichwerejectedbecausetherequisiteextrahardwarewouldbemorecomplicated.Rememberthatanintruderhasanaprioriprobabilityof2-56ofguessingtheconversationkeyathisfirstattempt.Unfortunately,VoydockandKenthaverecentlypointedoutthatbothoftheseschemesfordetectingmodificationstociphertextareinadequate[12].Ifanintruderswapstwoadjacentciphertextblocks,thechangemightnotbedetected.Wehavenotyetmodifiedourprotocolstorepairtîï\wî Åï\xî Œï\î Eï\wîíï\xîêï\ wîï\xî0ï\wî zï\xî!ƒï\wî&ï\xî&×ï\wî-Îï\xî.Ìï\wîïT&îÐ î #î ²îîµîîÓî§î Þî#nî&î(î.Ýî1ûî3üî5+î9îïQòî¾îî Ïî C îöî~î(î…îãî!·î$î&÷î*µî,mî.Ëî3Xî6Èî;CîïO½îÎîxî î °î î+îõîâî6î"®î)-î-6î3µî5î8äîïM‰îšîJ î äîÕîDîîÔî 3î% î(bî.î1’î4Xî8·îïKTîîüî î î‡îSîî\îÆî$7î(Êî,–î-×î0zî2?î4Gî9 îïI îIî°î ]î †îîMî îÀî"î&¯î+çî-Íî2Œî6Òî8­îïFëî`î îî Aî îõî7îÁîîîî"¢î%üî(›î.¬î3øî5Úî7.î;zîïD·îŸî (î ¸î <î!î›îbîkîzî!aî% î+êî.Vî0äî7_î:OîïB‚îîÞîî îÉîÚîCî:îÒ î".î(»î+:î-mî3î4øî9ªîï@N îhî žî³î|î‰î›îÈî\î$Wî'Ûî*™î. î0­î3jî:[îï> î ž îÞîOîvîôî î&Äî)Óî+wî-Ìî1åî4¨î7­î:Ôîï;å îùî ×î7 î î©î aî#’yîï6gî� î† wîÂï3îÀî ˆî $î®î)î>î îíîwî!j î(2î-»xî.4ï3î/ï3wî0rï3î1^ï3î3‰î6 îï0æîqîîžî Éî¬xî´ï0æîšï0æwî\ï0æî®î!Oî"ãî'î)•î/„î1‘î4î5¢î7mîï.²îîyî „îîiî îmî �î"ù î+®î1‰î4J î;zxîï,}wî>ï,}îï,}î”î î hî Ùî6îàîgî‰î ]î$¨î(Òî*¿ î1€î3wî4�î8Þî:’îï*Iî®îYî ý îæ îîî!Vî%¿î*Íî.…î0Ðî6Y îï( î)î íî 7îÚî¤îÃîî!î¸î ’î"Wî#Žî'Õî*wî.ÿî1î5Bî8–î9Ìîï%àîˆîŽîí îjîÂï#« xîüï#«î âï#«wî ñï#«îÂîìîbzîNï#«îþï#«wî ¦ï#«î#°î'Úî,Qzî.<ï#«î.×ï#« wî4‚ï#«î6Gï#«î9Àîï!wîÀî dî Çî)î®îãî\î{îÂî#qî%#î*Ãî/ î0Éî4Îî7Šî:¾îïBî î Uzî$ïBî¾ïBî(îÈwîÄïBî–ïB{îPïBî ïBwî!©ïBî"{ïBî&Gxî'öïBî(ÜïBwî*¯ïBî, î05î2Šî8î:’îïîTîìî Zî,î^ îî¶î!Nxî#Ñïî$œïwî&Çïî*Àî-þî0�î6î7ïî9<îïÙîXî »îUîµînî(îˆîÁîÜî&4î'¡î,uî.r î6Ûî9<îï¥ î–î Oî ®î,îãî'îBî®î!rî#mî)vî+$î0 î3(î5ˆ îïqî2î  î¸î/ îMîî� î$° î-Pî/xî/Æïþwî1Aïqî2Ïî6î;Èîï<î'îsî  î»îÏî{î îî î#ƒî%‚î'·î-Uî0Ÿî4î6Ïî:Ôîï îî îÊî îæî¹î îÝî%Ôî'Ý î0¢ î8¿î:‡îïÓî2îØî Bî çî‰ î¡îî^îéî!;î"Öî&Lî)î*î/+ î7î8¸îï Ÿî¼ îèî _ îhxîBï,wîDï ŸîÿîÞî@î$çî,î.t î5/ îï jxî³ï jî~ï jwîŠï jîdî Ýî=î?î?zî¥ï jî@ï jî8wîÔï jî!+î%=î'hî,™î1¿î4"î9Áîï 6î&î qî ~î. îðî )î#î%!î*–î-(zî/5ï 6î0†ï 6wî4Wï 6 î;zîïxî±ï�wî°ïîiî íî M îEîÛîsî¦î~îÂïÍ î 3î&î î¶î)î!�î&Åî)gî,bî/Ëî1°î5fî:öîï˜îì îwî(îeîîu î î$ î%‘î'„î,ßî0Ùî3ˆî8ùîïdîÏîƒî úî¹îÇîSî[îáî ‚î#àî&lî(Ìî.Àî1bî7lî91ÿ O « H«biSECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS5thisdefect.Weassumethatuserschoose(orareissued)sufficientlyrandomprivatekeys[9].Temporarykeys,CBCinitializationvectors,andconversationkeysshouldbegeneratedbytheauthenticationserversusingahardwarerandomnumbergenerator.Inthedescriptionsinthefollowingsections,wehaveomittedsomedetails.Thesedetailsarequitesystematic,beingthemodificationsneededforsecuredistributionofCBCinitializationvectors,foravoidanceoftransmissionsofciphertextforknownplaintext,andforminimizingtheamountofdataencryptedwithlongtermkeys.Allthesedetailsaregiveninfullinsection8.Weusethenotation{P}KtoindicatetheciphertextformedbyencryptingplaintextPusingencryptionkeyK.Ineachcontext,ifPisanencryptionkeyweintendstraightforwardsingle-blockuseofDES,andotherwiseweintendencryptionusingtheCBCmodewiththechecksumdescribedabove.4.AuthenticationThereissubstantialliteratureonprotocolsforimplementingthisnegotiation[1,5,10].TheprotocolweuseisbasedprimarilyonNeedhamandSchroeder's[10],modifiedslightlytoimprovesomeshortcomings,andrearrangedtomeetourefficiencygoals.Thisprotocolreliesonthepresenceofatrustedauthenticationservice.WeusetheGrapevinedistributedsystem[2]asourauthenticationservice.GrapevineprovidesadistributedreplicateddatabaseindexedbystringsknownasRNames.SeveralvaluesmaybeassociatedwithanRName.Onesuchvalueisusedastheprivatekeyforsecurityprincipals.Ourauthenticationschemecreatesanauthenticator.Anauthenticatorisencrypteddatathatoneprincipalcanusetoassuretheotherofhisidentity.WhenprincipalApassesanauthenticatortoB,theassuranceisbasedonB'sobservationthatsomeonewhoknewB'sprivatekey(namelytheauthenticationservice)promisesthattheimbeddedconversationkeywasgivenonlytoprincipalA.Bmayaswellbelievetheassurance,becausetheonlyalternativeisthatB'sprivatekeyhasbeencompromised.Theauthenticatortakestheform{CK,T,A}KBwhereCKisaconversationkey,AisA'sname,Tisthetimeatwhichtheauthenticatorwascreated,andKBisB'sprivatekey.Tisusedtolimitthedamagepotentiallycausedbyacompromisedprivatekey,bylimitingthelifetimeofanauthenticatortoafewhours.Toobtainanauthenticator,AcallstheRPCruntimesystemonA'shost,givingitA'sname,B'snameandA'sprivatekey.TheRPCruntimesystemcallstheauthenticationserviceremotely(withoutadditionalencryption)givingit[A,B,X]whereAandBaretheprincipalnamesandXisanon-repeating64-bitnumber.(Alternatively,Xmaybechosenpseudo-randomlyorrandomly.)Theauthenticationservicereturns{authenticator,X,B,CK}KAwî ÿï\xî Æï\î ï\wî&ï\xî$ï\ wîKï\xîjï\wî´ï\xî ½ï\wî%@ï\xî&ï\wî-ï\xî.ï\tî;éï\wîïT*î¢îÂïQõîdî Cî (î½î[î¯îîÍ î%öî+.î/âî3î6îïOÁxî¢ïOÁîlïOÁwî¤ïOÁ îµîäîË îóî"<î&çî)î/�î1¬î4; îïMŒî‘î;î eîmîŽîº îÂïKWî¥î îÃî…îøîî¬î çî$Bî)lî-î2fî6|î:àîïI#î‰ î nî8î— îîçî $î$] î+Çxî-ïI#î.JïI#wî0RïI# î83îïFïîLîÆî � îîÉîîÖî"î"¶î&Aî)_î,%î.p î5ºî8(îïDºî¹î¾î î;îUî›î‘îäîmî"½î%î(Äî*rî,ýî.«î3HîÂïB…î\îáî QtîÏïB…î€ïB…rîïCwînïB…î,îiîØî!"î#êî(Íî*Ù î1¹î5Ftî8ïB…wî9ŠïB…îï@Q îÛtî qï@Qwî cï@Qî Äî “îÄîñtîRï@Qwî½ï@Qî)î î"ôî%Šî'±î,î5“ îï>î‡xîRï>î8ï>wî�ï>î~ï>î Gî‚î»î î î!Åxî$6ï>î%ï>wî'ï>î+î./î0 î7 îï;èyîï6jî� wîÂï3îî´ îÇ îñî:îoî ï î)ðî,Ô î4>î:[îï0éî{î¯î 0î ¨î–î î²îî Ñ î(=î+Mî16î6 î7Æîï.µî” î Hîÿ îäî“îúî… î#ºîÂï,€îàî SîöîîdîîËîùî œ î)™î/î1’î4 î6oîï*K î'î Öîîçî¦ îÓî!�î(•î.Xî/¶ î6Ü îï(î¦î çî íîQîázî™ï(î–ï(wî�ï(îï(î"áî'î*'î," î2˜î5½î7·îï%ãîî6î ßî Kî‡î5î•î1îÇîî! îÂï#®î• î~îNîÅzî¦ï#®îVï#® wî!]ï#®î"žï#®î$á î-%î.�î4Ôî7Éî:ˆîï!yîÂîGî ¶î _î}îÖîpî#îPî ,î$?|î*ï!ywî+fï!yî/ƒî1n î9»|î;dï!ywîtîï>îï>wî|ï>îàî  îòtîØï>wîFï>tîªï>wî�ï>îõtîï>wî^ï>îÁî"î%6î&Æî*Ìî-# î5nî8îï tîàï îÓï wîrï tîï wîùï î ƒîHtî ï wî”ï î(îŒîcîÒî Zî%˜ î,�î14î3Yî4« îïÕî�î‹î †î§îîîÊîº î" î#¼î$åî'†îÂï  îìî 3î & tîÔï  wîNï  î`xîÂï  î–ï  wî�ï  î"Êî'Htî)Qï  wî*Dï  î+§î.üî3!tî4zï  wî5mï  î6Ðî:ëîï lî¬tîPï lwîBï lî�î îbxî'ï lîûï lwîÞï lîîiî"dî$° î-”î2î7®îï 7 îx î Ìîîtî ïî îäî¾î!*wîïÎtî$ïÎwî§ïÎtîjïÎwî íïÎî Lî¸îŠîÚtî�ïÎwîïÎîŒîÁ î(˜î,›î2»tî;ÈïÎwîï™îîõî ‡înî2 î¼î ” î)Œî.tîÞïdî î€î!Oî#)î%�rî&Mïò k « H«bå6SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLSwhereKAisA'sprivatekeyandCKistheconversationkey,alsoimbeddedintheauthenticator.TheRPCruntimesystemonA'shostmaynowobtaintheconversationkeyandauthenticator,andisassuredthatitandCKwereissuedbytheauthenticationserviceforcommunicationbetweenAandB.Additionally,theRPCruntimesystemgeneratesapermanentlyuniqueidentifierfortheconversation.LaterwhenAaskstheRPCruntimesystemtomakearemotecallusingthisconversation,ithasavailabletheauthenticator,theconversationkeyandtheuniqueidentifier.Thefirstpartoffigure2showstheoperationofcreatingaconversation.Thepermanentlyuniqueidentifierofaconversationiscreatedbyconcatenatingtheuniqueidentifierofthisprocessorwithasequencenumber.Whentheruntimesystemisfirststarted,thissequencenumberisinitializedfromaonesecondreal-timeclock,andthevaluesusedforuniqueidentifiersneverexceedthecurrentvalueofthatclock.Thisrestrictstherateofgenerationofnewconversationsonasingleprocessortoalongtermaverageofonepersecond,althoughtheburstratemayoccasionallyexceedonepersecond.Notethatinordertoreturntheauthenticator,theauthenticationserviceusestheprivatekeysofbothprincipals.SincetheGrapevinedatabaseisdistributed,bothofthesekeysmightnotbeknownbyanysingleGrapevinehost.SotorespondtotherequestaGrapevinehostmayneedtocommunicateinasecurefashionwithanotherGrapevinehost.TheGrapevineserversarecapableofcommunicatingsecurelyamongstthemselves,sincetheyarethemselvessecurityprincipalsregisteredinapartofthedatabasethatisreplicatedoneveryGrapevinehost.Itisimportanttorememberthattheentiresecurityofthisschemedependsonthesecurityoftheauthenticationservice'sdatabase.Ultimately,thismustdependonthephysicalprotectionofthehostsmaintainingthisdatabase.5.MakingSecureCallsThestructureemployedforourRPCpackage(aswehavedescribedintheearlierpaper[3])isasfollows.Acallerinitiatesaremotecallbymakingalocalcalltoaspeciallyconstructeduserstubmodule.ThisstubtakestheargumentsofthecallandanidentificationofthedesiredprocedureandplacestheminoneormorepacketswhichitpassestotheRPCruntimesystem.Theruntimesystemisresponsiblefortransmittingthepacketsreliablytotheremotehostandwaitingforaresponse.Intheremotehost,thepacketsarereceivedandarepassedtotheappropriateserverstubmodule(alsospeciallyconstructed).Theserverstubunpackstheargumentsandmakesanordinarylocalcalltotheappropriateprocedure.Whenthislocalcallreturns,theserverstubtakestheresults,placestheminoneormorepackets,andtheRPCruntimesystemcommunicatesthembacktothecallermachine,wheretheyaregiventotheuserstub.Theuserstubthentakestheresultsandreturnsfromtheoriginallocalcall.Thisstructureisdepictedinfigure1,andisdescribedinmuchmoredetailintheearlierpaper[3].Theearlierpaperalsodescribesourbindingmechanism,wherebyacallerdetermineswhichhostimplementsadesiredremoteprocedure.tîïYàwî ÅïYàxî ŒïYàî EïYàwîíïYàxîêïYà wîïYàxî0ïYàwî zïYàxî!ƒïYàwî&ïYàxî&×ïYàwî-ÎïYàxî.ÌïYàwîïQðtîïQðî ïQðwî‚ïQðtîîïQðwîáïQðî AîÞîttî+ïQðî(ïQðwîŸïQðî îj î"cî%Qî(î.•î0Cî2£ îOïO¼xî0ïO¼îïO¼wî ïO¼îDtîÈïO¼îùwîìïO¼îDïO¼îUîXîeî qî$¿î'' î/)î1Èî4ˆ îïM‡îºî)î î çî ?tîùïM‡î÷ïM‡wîpïM‡îÄîêîéîK î'Fî+Ïî. î7ÅtîïKSwî‹ïKStîWïKSwîIïKSîÒ î+xîŸïKSîsïKSwî~ïKSîÉîXî$uî%² î-¿î2| î8‚î:ÔîïI î†î tî–ïIwîæïIî¬xîäïIî¸ïIwîˆïIî˜î!ìî#sî'î(î,‚î.æî2hî4â îïFêîdîçî ¯î  îÕîB îIî!ìî$±î'î+Ô î2½î5£î8‰î;zîïDµîî7î Dî £îÍî†î½îç îÂïB�îË î ôîÍ îðîÚî4 î$]î%úî*ôî- î5ûî8‹îï@L îÿîÃî pî�î¶îëîßî þî%"î'�î,Ðî1Wî2Îî5²î:’îï>îî Fî É î7î¶îøî¼îfî%Oî)Tî,#î.›î2áî65î8‹îï;ä îzî GîÐî2îþî«îfî7î"«î%Èî*áî-Cî0î1à î8Šî:Eîï9¯ îqî jî ‡îeîlî î*î7îpî#bî%î'­î*î.òî4¢î6ôî:qîï7{î î ¥î+î×îLîÂï5FîJî *î éî¯îoî¯î îÝî"N î+Xî/ðî2úî5kî:îï3îÙî5 î ›îoîîîÒîŒî! î(�î+Ýî-µî1^î4—î8®î;Cîï0Ýî‘î—î Bî 8îîðîîºî!î"Àî%*î* î+=î2 î5î8î;…îï.© îî 8î mî±î�î¶îÌî#›î'†î*iî18î5Ôî83îï,tî’ î î9î‹ î¬î÷î"àî% î+Õî0Ä î6è îï*@î®îØî¼îuî Ôîpî>î© îzîï*@î¡ï*@wî…ï*@î&IîÂï( îGîÀî /î ëî�îlîÙîÓî"÷î$½î'lî,Yî1Õî3éî6Vî;zîï%×îX î Hî¢î î(î Áî$!î)î+î-Xî2� î9#î:Ôîï#£î~ î î µyîï%î�î­î =wîÂïÙîŸî bî½îÿxî�ïÙîdïÙwî`ïÙî1î!^î#Šî&Öî-î.ºî1î5gî9Nî;Èîï¥î«î>îÇî yî—î¾îbîêîãî Éî!ðî%3î'»î)fî*�î0 zî7lï¥î8)ï¥î:Mwîïpîî Dî dîûîuî=îî‰î .î#î% î-�î/Tî1Íî6°îï<îÊîõî ‘î Qîîæî‹î}îžîî#<î$ýxî'nï<î(Bï<wî*Lï<î/•î5î7üîïîµîZ î Æî< î"î»îÔî%î&éî)‚î.bî1•î4†î9“î< îïÓî~îKî ©îOîŸîýîÛî-î!™î$Oî&¡î+î,²î/ zî6mïÓî6ñïÓî:Mwîï ŸîÿîDî Ó î|îSî^î cî%»î(î.Çî1}î5µî7¤îï jî8îµîTî ¥ îö î8îBîÕî" î$‰î)†î+×î/Õî2Ëî6;î8Œîï 6î-îÊî Œî Lî#îËîîáxîUï 6î)ï 6wî4ï 6î$î) î2î5·î9î:ÔîïîÛî ÝîîQîÊî¤îyîþîî#Jî&Hî)gî,’î/Þî3�î6î:|îïÍîµîî î‹îÓî=îYîî …î&î'Çî+Ëî-Zî0î1€î7­î9\îï˜îyî+î¾î î-îõî—îUîî Fî"øî(Æî+7î03 î7¤îïdî*îß î åîóîí îVî€î Iî$ð À « ?H«_åSECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS7<==î îÂïqîËî ¹î Ôîxî_ïqî3ïqwî ïqî$î‚î!jî$}î)ãî0î1î4.î7xîï<î îˆ î ºî³î îUîmî×î!î%tî)Öî,v î3Yî7Ýî:Ôîï îî Îî îûî¾ îÒî _î%)î(dî*uî.î0íî2þî7Bî9ŠîïÓî>îªî Öî !îIîwî¬î_îîîNî#]î%î)óî,î/¡î2×î5: îï Ÿ îùî î˜îeî/î˜î î"<î& î)m î0‰î3˜ î:|îï jîû î÷î ºî $î’îVî8îÚî!�î$×î)=î*²î1xî4Òï jî5�ï jwî7¯ï jî:Ôîï 6î…î Ýî¸î‚îîîóîƒî"”î$zî'î+�î1 î7Åîï îí î@î©îœîÒî•î!Aî#Öî)8î*ðî-Zî1Éî4Ìî7ŽîïÍîU î<î êî >î˜î¹îeî¹î —î%¸î'eî)üî.Lî3î4Âî7Xî:©îï™îuîÕzîï™î¶ï™î ± wîgï™î¤îî îÙtî «ïdî ¨ îî °î/‹ÿ « H«aÑÿìÿûÿìºÿîÿïÿü Ýÿ캋M /: 'ùúøÿîÿáÿïàÿþ?@ùúøÿîðÿïðÿþ ùúøÿîÿáÿïÿáÿþ??ùúøÿîðÿïðÿþ ùúøÿî ðÿïðÿþ ùúøÿîðÿïðÿþ ùúøÿîðÿïðÿþ ùúøÿî ðÿïðÿþ ùúøÿîðÿïðÿþ ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ ùúøÿûùúøÿûùúøÿîðÿïðÿþ ùúøÿûùúøÿûùúøÿîðÿï�ÿþ!!ùúøÿûùúøÿûùúøÿîðÿï ðÿþ!!ùúøÿî ðÿïðÿþ ùúøÿûùúøÿîðÿïðÿþ!!ùúøÿûùúøÿî ðÿïðÿþ!!ùúøÿûùúøÿûùúøÿîðÿïðÿþ!!ùúøÿûùúøÿûùúøÿî%àÿïàÿþAAùúøÿûùúøÿûùúøÿîðÿïðÿþ ùúøÿûùúøÿûùúøÿîÿáÿïÿáÿþ??ùúøÿî%ðÿïðÿþ!!ùúøÿî-ðÿïðÿþ ùúøÿî%ðÿïðÿþ!!ùúøÿî%ðÿïðÿþ ùúøÿî/ðÿïðÿþ ùúøÿî/ðÿïðÿþ ùúøÿî5ðÿïðÿþ ùúøÿî7ðÿïðÿþ ùúøÿî7ðÿïðÿþ ùúøÿî7ðÿïðÿþ ùúøÿî=ðÿïðÿþ ùúøÿî/ðÿïðÿþ ùúøÿî-ðÿïðÿþ!!ùúøÿî5ðÿïðÿþ!!ùúøÿî5ðÿïðÿþ!!ùúøÿî-ðÿïðÿþ!!ùúøÿî6ðÿï�ÿþ!!ùúøÿûùúøÿûùúøÿî;ðÿï ðÿþ!!ùúøÿî%àÿïàÿþ@@ùúøÿûùúøÿî7ðÿïðÿþ!!ùúøÿûùúøÿî/ðÿïðÿþ!!ùúøÿûùúøÿûùúøÿî;ðÿïðÿþ!!ùúøÿûùúøÿûùúøÿî?àÿïÿáÿþ@?ùúøÿûùúøÿûùúøÿî%àÿïÿáÿþ@?ùúøÿûùúøÿûùúøÿî%àÿïÿáÿþ@?ùúøÿîàÿïÿáÿþ@?ùúøÿîàÿïàÿþAAùúøÿî:ðÿïðÿþ!!ùúøÿî;ðÿïðÿþ!!ÿò�ÿ!¾H ‹H *@  Ëùúøsî ïdðùúøsî ïdðÿ ùúøsî ïdðÿ ùúøsî ïDðÿ ùúøsî ïdðÿ ùúøsî€ ïdðÿ ùúøsî` ï dðùúøsî ï dðÿ ùúøsî0 ïDðÿ ùúøsî À ïdð ùúøsîÀ ïdð ÿ ùúøsî ïdðùúøsî ïdðÿ ùúøsî ï dðùúøsî ï dðÿ ùúøsî.€ ïdðÿ ùúøsî&` ï„ð ÿ ùúøsî/à ï„ð ùúøsî9À ïdðÿ ùúøsî'` ïdðùúøsî0 ïdðÿ ùúøsî ï Dðÿ ùúøsî8 ïdðÿ ùúøsî: ïdðÿ ùúøsî8 ï dðÿ ùúøsî0 ï dðÿ ùúøsî0 ï Dðÿ ùúøsî' ï dðÿ ùúøsîÀ ï„ðùúøsîà ï„ð ùúøsî  ï ¤ð ùúøsî ïdðÿ ùúøsî ïdðÿ ùúøsî ï$ð ùúøsî8 ïdðÿ ùúøsî0 ïdðÿ ùúøsî4 ï$ð ùúøsî ïdñ%X «Ee>`CDU8SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS<== not foundDSend RFAo Lookup ConvID Store CK, etcDecrypt Call PkttRPC+StubuRPC+StubuUserSCaller machine Callee machine Server Do callReturnl Encrypt, SendDecrypt Call PkttDo callReturnlGetAuth[A,B,X]k{ {CK,T,A}KB, X, B, CK }KAsCall[ConvID, {CallID, ....}CK ]"RFA[rfaID, ConvID, {CallID}CK, Y ].!Result[ConvID, {CallID, ....}CK ]"Call[ConvID, {thisCallID, ...}CK ]T$Result[ConvID, {thisCallID, ...}CK ]ACalltCalltGetAuth New ConvIDvStore CK, AuthReturnC Encrypt, Send Wait for pktD Lookup ConvIDrespond Wait for pktDDecrypt Encrypt, Send Wait for PktDDecrypt Encrypt, Send%[rfaID, B, {CallID,Y}CK, {CK,T,A}KB ]tîï]Cwî Åï]Cxî Œï]Cî Eï]Cwîíï]Cxîêï]C wîï]Cxî0ï]Cwî zï]Cxî!ƒï]Cwî&ï]Cxî&×ï]Cwî-Îï]Cxî.Ìï]CrîïÚ1}îÂï¥îêrî‰ï¥ îîúîðî�îîlî!ðî#lî%†î(øî,²î.Ìî3{î4÷î6 îïqîJîÒ î ¨ îÕ~î6ïqîÕïqrî|ïqî9ïqîƒ î| î$Q~î$³ïqî%}ïqrî(tïqî(Õïqî)Üî,/î.Uî0¹î4Rî5Lî95îï<î7î¼î ³î JîîB î×î'îSî!î%êî'Lî+­î-;î/3î1_î4õî6ƒî;�îï î`îE îowîÂï Ÿî'î ´î sî £î îî¹îéî (î#î%w î-v î3oî4áî9mî;…îï kîÆî&î ²î …î—î î8îJî%î!©î(eî*Bî,Åî1Eî2Õ î:[îï 6îSî �î ùî7îÕî*îèxî7ï 6îï 6wîúï 6î%Aî&œî*¿î/wî1 î3±î7‚îïîëîgî Þî fî øîCîêî îž î"¬î(7î,Iî0âî2úî5î:|îïÍ î4î êî…îJî4î î#î çî"Üî'gî,lî2¼î6î:Ôîï™îìî !xî ùï™î Íï™wîÃï™îùîtîþî$î#œî%ûî,’î.Jî0©î5î6±îïdîLî©î î“îºî¥î†îGî°î’îHî 6î%î(`î*!î+Šî,±î2£î4Yî7êî:Q´ « ÜH«cHìÿìÿûÿì[Xÿîÿïÿü-¬ÿì´[X‹'ö 84 'ùúøÿî ðÿï1ðÿþ!!ùúøÿîðÿï)ðÿþ!!ùúøÿîðÿïðÿþ 2 ùúøÿî-àÿï5àÿþ@@ùúøÿî-àÿï)àÿþ@@ùúøÿîðÿï1ðÿþ ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿî-ðÿï)ðÿþ ùúøÿîðÿï!ðÿþ!!ùúøÿî-àÿï3àÿþAAùúøÿîðÿï+ðÿþ ùúøÿîàÿïÿáÿþ@6?ùúøÿîðÿï!ðÿþ ùúøÿûùúøÿûùúøÿî-àÿï#àÿþAAùúøÿîAàÿïÿáÿþ@&?ùúøÿî ðÿï3ðÿþ ùúøÿî ðÿïðÿþ ùúøÿî ðÿïðÿþ 2 ùúøÿî ðÿïðÿþ 2 ùúøÿîðÿïðÿþ ùúøÿîðÿï3ðÿþ ùúøÿîàÿï5àÿþ@@ùúøÿîðÿïðÿþ 2 ùúøÿîàÿïÿáÿþ@?ùúøÿîàÿïÿàÿþAAùúøÿîàÿï3àÿþAAùúøÿî-ðÿïðÿþ " ùúøÿî-àÿï%àÿþ@@ùúøÿî7ðÿïðÿþ " ùúøÿî-àÿïÿáÿþ@?ùúøÿî9ðÿïðÿþ " ùúøÿî9ðÿïðÿþ ùúøÿî?ðÿïðÿþ " ùúøÿî9ðÿï#ðÿþ ùúøÿîðÿïðÿþ ùúøÿî-ðÿï#ðÿþ ùúøÿî ðÿï!ðÿþ!!ùúøÿî-ðÿïðÿþ ùúøÿî-àÿïÿàÿþAAùúøÿîðÿïðÿþ ùúøÿîðÿïðÿþ ùúøÿûùúøÿîðÿï ðÿþ ùúøÿûùúøÿûùúøÿîðÿïðÿþ!!ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿîðÿïðÿþ!!ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿîðÿïðÿþ!!ùúøÿûùúøÿûùúøÿî ðÿï ðÿþ!!ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿîAðÿï'ðÿþ!!ÿî>ðÿï'ðÿþ!!ÿî;ðÿï'ðÿþ!!ÿî8ðÿï'ðÿþ!!ÿî5ðÿï'ðÿþ!!ÿî2ðÿï'ðÿþ!!ÿî/ðÿï'ðÿþ!!ÿî,ðÿï'ðÿþ!!ÿî)ðÿï'ðÿþ!!ÿî&ðÿï'ðÿþ!!ÿî#ðÿï'ðÿþ!!ÿî ðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿî ðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîðÿï'ðÿþ!!ÿîÿðÿï'ðÿþ!!ùúøÿîAðÿï ðÿþ!!ÿî>ðÿï ðÿþ!!ÿî;ðÿï ðÿþ!!ÿî8ðÿï ðÿþ!!ÿî5ðÿï ðÿþ!!ÿî2ðÿï ðÿþ!!ÿî/ðÿï ðÿþ!!ÿî,ðÿï ðÿþ!!ÿî)ðÿï ðÿþ!!ÿî&ðÿï ðÿþ!!ÿî#ðÿï ðÿþ!!ÿî ðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿî ðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîðÿï ðÿþ!!ÿîÿðÿï ðÿþ!!ùúøÿîðÿïðÿþ ùúøÿî7ðÿïðÿþ!!ùúøÿûùúøÿûùúøÿî7ðÿïðÿþ!!ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿî7ðÿïðÿþ!!ùúøÿî7ðÿïðÿþ!!ùúøÿîKðÿïðÿþ!!ùúøÿîAàÿï)àÿþ@ @ÿò×ÿ_ 8 ‹&öþ L 6 ùúøpî ïdñùúøsî  ï4Dðÿ ùúøsî/ ï:dðÿ ùúøsî1à ï4dð ùúøsî2 ï2dð ùúøsî.À ï0dðùúøsî/€ ï.dðÿ ùúøsî, ï$dð ùúøsî, ï"„ð ÿ ùúøsî, ï„ðÿ ùúøsî, ï Dð ùúøsî, ïdð ùúøsî, ïdðÿ ùúøsî € ï7ðÿ ùúøsî.  ï'Dðÿ ùúøsî@ ï7ðÿ ùúøsî  ï:dðÿ ùúøsî0€ ï)$ðÿ ùúøsî9 ï'$ðÿ ùúøsî8  ï„ðùúøsî8€ ïdðÿ ùúøsî, ïdð ùúøsî, ï dðÿ ùúøsî8  ï „ðùúøsî8€ ïdðÿ ùúøsî ï5„ðÿ ùúøsî ï/„ðÿ ùúøsî ï%„ðùúøsî ï„ð"ÿ ùúøsî ïdð!ùúøsî ï $ð"ÿ ùúøsî ï„ð$ÿ ùúøsîÀ ï$$ðÿ ùúøsîÀ ï $ðÿ ùúøsî à ï4dðùúøsî ` ï2dð ÿ ùúøsî ï.dðÿ ùúøsî € ï,dðÿ ùúøsî à ï$dð ùúøsî   ï"dð ÿ ùúøsî ïdð ùúøsî @ ïdðùúøsî   ïdð ÿ ùúøsî ïdðùúøsî @ ï dð ùúøsî   ï dð ÿ ùúøsî ïdðùúøsî, ïdð ùúøsî  ï„ð%cDê «$R?@Bä°SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS9Thisdeterminationisjustasitwouldbefornon-securecalls,andusesthesamedatastructures.Notethatweareusingthemechanismsforeliminatingduplicatesthatmayhappeninanytransportprotocoltosimultaneouslyeliminatereplaysmaliciouslyinjectedbyanintruder.(Thisisdiscussedfurtherinsection6.)Atypicalsecurecallisshownattheendoffigure2.Wehaveassumedtheexistenceintheserverofamappingfromconversationidentifiertocallerandconversationkey.Further,thetableusedbytheservertoeliminateduplicatecalls(whichgivesthesequencenumberofthelastcallfromeachprocessoneachhost)ispartofthesecurityarrangements,sinceitisthisthatpreventsanintruderreplayinganoldcall.Clearly,thesemappingsmustbeestablishedinitiallyinasecureway,bysomeformofconnectionestablishmentprotocol.Inourpackage,thisisachievedbyatechniquethatalsopermitstheservertodiscardthisinformationwhentheconnectionisidle.Thisisachievedbyaformofcall-back,knownasarequestforauthenticator,orRFA.Whenaserverreceivesacallpacketwhoseconversationidentifierisunknowntotheserver(andwhich,therefore,theserverisunabletodecrypt),theserversendsanRFApacketbacktothecallingmachine.TheRFApacketcontains[conversation-identifier,{call-identifier}CK,Y]whereYisanon-repeating(orpseudo-random)64-bitnumber.Sincetheserverdoesnotyetknowtheconversationkey,itcannotperformanyencryptionsordecryptionsyet,but{call-identifier}CKisavailabletotheserverfromtheinitialpartofthe(stillencrypted)packet.(ThisencryptionisdefinedtousepurelyCBC,withnochecksum.)OnreceivingtheRFA,thecaller(whoisA)returnsapacketcontaining[B,{call-identifier,Y}CK,authenticator]Thisallowstheserver,B,toobtaintheconversationkeyandA'snamefromtheauthenticator.Thecallidentifierintheresponseassurestheserverofthecurrentcallsequencenumberforthecallingprocesscontainedinthecall-identifier.TheserverdecryptstheoriginalcallpacketandverifiesthatitscallidentifiermatchesthatintheRFAresponse.ThenumberYboundinwiththecallidentifierintheRFAresponseassurestheserverthattheRFAresponseisnotaretransmission,andhencethatthecallisnotbeingreplayedbyanintruder.TheinclusionofB'snameinthisresponseispurelytoenabletheRPCruntimesystemtodecrypttheauthenticatorwithoutconsultinghigherlevelsoftware;anincorrectnameherewouldcausethepacketdecryptiontofail.TheuseofthisRFAprotocolforthefirstcallofaconversationisshowninthemiddleoffigure2.Wehavenowestablishedtheinformationtheserverneedsforacceptingsteadystatecalls.Thishascostustwoextrapackets,whichisminimalforanyformofconnectionestablishment.TheservermaydiscardthisinformationafterasuitableperiodwithnocallsfromA,sincetheinformationcanbeobtainedbytheserverwheneveritwishes.Thuswedonotrequireaconnectionterminationprotocol.6.PreventionofReplayedCallsThemostcomplicatedofthethreatswearepreventingisthatwedonotletanintrudercausewî ÿï\xî Æï\î ï\wî&ï\xî$ï\ wîKï\xîjï\wî´ï\xî ½ï\wî%@ï\xî&ï\wî-ï\xî.ï\tî;éï\wîïT(î? î 9î Êî�îbîÝî/îEî¦ î#Æî'Rî*.î-Kî/Ïî3qî6š îïQôîuîAîgî ¸î`î¾ îsî® î!Þ î(Tî+!î."î3 î4·î7VîïO¿îyî2 î–î�îZ î"–î'Íî)Òî+Íî2î5´î7*îïM‹î©îWî ôî }î î{îµî?î«îúî!“î#òî&ªî(cî,dîÂïKVîBîîîYî,îÏî%î'îÖî õî&§î* î1ò î7Úî9îïI!î± î £îîmîÆî'î\îPî ©î$®î&Vî,Lî29î5Aî9ÁîïFíî¬îàîXî\îîÓîªî\îÙî$ùî'Kî*Çî.†î0=î3mî5rî8îïD¸ îÉî 0î yîÙînî0î¨îŒî Øî&Ôî(¸î+î.cî3wî6óîïB„î[î? î 9î+îÌîéîî8î'î ­î$î%³ î,¢ î54î;dîï@Pî�î.î Óî Cî÷î÷î%î€îRî!#î&î(î,�î.Bî3î5© îï>îôî’ î Ìîvî†îÞîˆîxî ²î"î%¿î'· î.î2Ùî4Åzî6-ï>î6±ï>î; îï;ç wî·ï;çî„ï;ç{î 8ï;çî ï;çwî ~ï;çî ¿ï;çîÇîáîÞîúîî�î#Úî'ø î/á î5Äî7 îï9²î°îîî Oî· î÷îXîeîÒî"Zî$ î)Òî,3î0@î4xî5òï9²î6Æï9²wî8Øï9²îï7~îGîöîUî ºîxîóï7~îÇï7~wî×ï7~î3tî0ï5Iî.îkrî)ï5Ötî*¨ï5Iî+�î-wîï3tîï3wî�ï3î÷î îéî% îqî!gî'lî+ î-î1Šî4¹î7,î9tîï0àîp î xî vîÜîgîÏî î"îî$ î,1î.âtî1rï0àî2#ï0àrî;"ï1mwîï.«îŽîjî ;î ¼îêîsîôîîîáî!cî$ž î+œî1î4Ë î;Èîï,wîî¸î 1xî …ï,wîPï,wwîÔï,wîµï,wîÔîß î”î÷î%×xî(;ï,wî)ï,wwî*›ï,wî+|ï,wî-àî1™î5tî6‹ï,wwî7~ï,wî8€îï*Bî*î… tî+ï(î)îîérî�ï(›tî!ï(î" î+ wîÂï%Ùîäî î �tîîï%Ùwîáï%ÙîÅî|îÉî0 î#1î%Ïtî(Žï%Ùwî)�ï%Ùî*êî.²î2!î4‰ îï#¤îøî£ î µî ‚îîÆî�î î!8î#î%�î*yî-#î3+î8wî:Ôîï!pî›î ¤î%î îžîWî!eî%§î+Wî-ìî3+î5ëî:|îï;îÒî«î �î $ î!îyîRî xîsï;îGï;wî!bï;î'÷î*Útî0ï;wî1‘ï;î5÷î7¯î:Ôîïîš îšî Wxî Åïî ™ïwî¸ïîkî!îŽî ©î#†xî%óïî&Çïwî(æïî.šî0î2—î3ÏîïÓîÛîõî æî hîî¤î<î*îçîî!î'“î*�î0�tî2hïÓwî3[ïÓî4ßî8Áî:’îïžî¤îî [î îkxîÉïžî�ïžwî’ïžîÈî Aî!îî&âî)? î1‘î6› îïjî]î±îCî@î î×îÿî!;î$þî'kî+Ô î2¼î4xî7Ùî:¾îï5î¹xî[ï5î/ï5wî@ï5î ®îëîKî#î®îgî� î!‰î"õî'Dî(òî+Rî/ùî1²î5´îÂïîFî†î ƒ î„îÝ î`î¹î"¿î&™î(Ðî.Þî3î6;î:îïÌîŸî–î�î dîîaî™î.îÄî!+î#õî'†î)h î0� î:[îï ˜î÷îåî �î îŒî²îÆîÆî# î&î(î*ùtî.Jï ˜wî/=ï ˜î0î3`î5© îï cîƒîjî î î[î^îŠî×îúî"oî$�î&‹î(÷î-¶î.× î5Ê îï /yîï°î� îpî îwîÂïdî¦î  îÈî�îùî�îµî î$ûî&sî)Mî+�î-“î0î2î4î9~ ¿ « H«bU10SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLStheservertoinvokeacallmorethanonce.Basically,thisisachievedbythemechanismthateliminatesduplicatecallsbasedonthesecurelytransmittedcallidentifier.Thismechanismisinitializedsecurely(andrestoredsecurelyiftheserverdiscardsit)bytheRFAmechanism.However,thereareseveralsubtletiesinthis.Notethatwespecifiedthepermanentuniquenessoftheconversationidentifier.Ifsomehowanintrudercausedaprincipaltore-useaconversationidentifierfromsomepreviousconversation,theonlypossibleadverseeffectwithprobabilitymorethan2-56isdenialofservice.Thiswouldhappeniftheserver'stablestillcontainedanentryforthatconversationidentifier:inthatcase,theserverwouldincorrectlybelievethatitknewtheconversationkey,andsothechecksumwouldlookwrongwhenthecaller'spacketsweredecrypted.Areplayedcallwouldbeacceptedonlyiftheconversationidentifierwasre-usedwiththesameconversationkey.Sinceconversationkeysareallocatedsecurelyandrandomlyonthecaller'sbehalfbytheauthenticationservice,thereplayisacceptedwithprobability2-56.Asimilarargumentappliestotheidentifierofthecallingmachine.Weusedthiswhenlookinguptheconversationidentifierintheserver'stable,andwedidsobybelievinginformationtransmittedunencryptedinthepacketheader.Theonlyeffectoftheintrudermodifyingthepacketheaderwouldbethatwewoulddecryptthepacketwiththewrongconversationkey(exceptfora2-56probability),andthiswouldbedetectedbyourchecksumarrangements.Becauseofthis,wecanoptimisebynotincludingthecaller'smachineidentifierinthesecurepartofthepacketatall.Wealsoarerelyingontheuniquenessofthecallidentifiers.Thishasthreeparts:amachine-relativemonotonicsequencenumber,amachine-relativeprocessidentifier,andaglobalmachineidentifier.Thesequencenumberdoesnotneedtobepermanentlyunique,sinceforacalltobeconsideredatallitspermanentlyuniqueconversationidentifiermustbeapprovedbythecallerrespondingtotheRFA.However,withinaconversation,thesequencenumbermustbenon-repeating:sinceweusea32-bitfieldthislimitsusto232callsperconversation.Othersecurityconsiderationsrestrictthereasonablelifetimeofaconversationtolessthanthis.Thecallercanstraightforwardlyensurethemachine-relative(non-permanent)uniquenessoftheprocessidentifier.Themachineidentifierisnottransmittedwiththecallidentifier,sinceitmaybepickedupfromthepacketheaderandverifiedwhilelookinguptheconversationidentifier.Again,thepossibilityofanintrudercausingacallertouseaduplicatemachineidentifierisnotaproblem(beyondthe2-56probabilityofidenticalkeys),sinceitwouldcausetheservertodecryptthepacketusingthewrongconversationkey.TheperiodforwhichaservermaintainstheconnectionstateinformationmustbeguaranteedtobelongerthanthemaximumlengthoftimeforwhichAiswillingtocontinueretransmittingacallpacket.Otherwise,anintrudercouldwaituntilacallhasbeeninvoked,suppressallfurtherpacketsbetweenBandA,waituntilBhasdiscardedthestateinformation,andthenallowaretransmissionandsubsequentpackets(includingtheRFA)getthrough.Thiswouldhavetheeffectofcausingthecalltobeinvokedtwice.Thisremarkablyunlikelyeventisdepictedinfigure3.Itispreventedbytheserverkeepingitsstateinformationforalongenoughperiod.Notethatthisonlyrequiresclocksthatrunatapproximatelythesamerate,notsynchronizedclocks.tîï\wî (ï\xî ïï\î ¨ï\wîPï\xîMï\ wîuï\xî“ï\wî Ýï\xî!æï\wî&iï\xî';ï\wî.1ï\xî//ï\wîïT.î›îâîÌî �îæî¬îzîÜît î#·î&“î(:î.&î0]î2÷î:eîïQú îÌî îeî‘îâîŒî# î&­î)‚ î0æî4Jî;ÈîïOÅ îKî Žî´î÷î:î�îåî çî&î'äî)Õxî,+ïOÅî,þïOÅwî/ïOÅ î6þîïM‘îŠîÝî n îwî%îÂïK\î4îþî "îÙzî5ïK\îåïK\wîÓïK\ î ìî" î$ü î,ð î3¶î54î;CîïI'î`î ãî îáî–îµîæ îå î%Þî)Lî,æî2| î:ÔîïFóîîRî Aîî î î®î!Ïxî"ïG€wî$zïFóî%àî)þî+²î1 î4î8IîïD¾îjîÑîÃî 3îÜî0î)îÅî îá î'â î.ãî0™î3pî6¿î9'îïBŠî* î õî£îmî¿îdî¿ î!³î$œî'Oî)î+jî1¼î5æî8ûîï@Vî£îïî nî:îy î‘î î “î# î'&î)î.™î1 î2îî5: îï>! îãîî OîZîªî îî!Rî$ø î,áî/ëî2/î7æîï;íîî „î ×î‚î_îåî-îØ î&î+Hî-óî2mî4%î:îï9¸ îxî¸ï:Ewî 3ï9¸îÂï7ƒîHîÈîìî�î6î� î|î/î!ˆî%çî,;î.¿î1õî4‘î8@îï5Oî÷î: î  îíîîÃî�î4î Ïî"Ûî%4î&Üî(¼î.‡ î5õ îï3 îî ñî zîÿîµî·îúî ïî"Òî%[î*Þî1žî4(î8¬îï0æîaîƒî ƒî Üî=îdîöîƒîÏî"aî&Ë î.öî1½î6¹î9(î:ƒxî;4ï1swîï.² îóî Åî €îÉîÔîiîî$î$• î.#î3î5Rî8fî:¨îï,}î�î‹î îîtîî‰ î"|î$*î&‰î*Ãî-§î/`î1¿î6î7³îÂï*Hîµîëî §î¬îîã îiî‹î"Tî%H î-lî0ïî3Íî7¿î< îï(î Šî–î°îfîÁî)Kî.P î4Ìî7µî9îï%àî‰ î `î<î(îYî�î î#gî%zî'ï%àî'¿ï%à wî.¾ï%àî3Âî79î9zî:¨îï#«î¢î† î _î ëî Îîœ îˆî$ î$ î)öî-Qî/5î5=î7,î9îï!w îýîŒxî Ëï!wî Ÿï!wwî ,ï!wîLï!wîaî†î� î!Áî$î)Éî.Öî2î3ï îïBîwî¢îî Gî Bîvîîéî¼înxîïÏwîÁïBîÓî"L î+(î/"î4< îïî¢î î ïî îÒî îîÑî"vî%«î)Hî,/î/óî2ŽîïÙî›î/î¼îŒ î#Þî%Ìî(`î-i î4¢î7¯îï¥ îãî>î ¢ îÐîÛî*î¤ îÞî"Aî#†î&zî(Zî,ºî.¼î2î4bî8¬îïpîœîŠî #îûîñî5 î î"©î&ñî)5 î/›î18î3 î8Iîï<îî«î@î›î «î†îñ îÉîîwî‡î$ñî*;î,�xî-1ïÉwî/ï< î6î7£îïîìî^îµî ãî˜îøîî³î©î î$cî( î*lî.¥ î6žîÂïÓî®î î lî�îËîêî=î° î%Àî) î0¡î4î6! îï žîÀîÃîî Oî ÀîSîžîiî îîtî$ï žwî%–ï žî'î+«î-jî3" î< îï jî«î! îî+î£îŽî§î!î"Wî%î'–î+î0Ìî6{î8‹îï 5î'tî Üï 5wî šï 5tî˜ï 5wî‹ï 5î®îîtî|ï 5wî:ï 5îöî#gî&î)… î1¯î4­î8î< îï î î Ä îîîÎ î\xî »ïî!�ïwî#ïî$ïî&cî,xî/’î3Áî7î9hîïÍîÄî¸î #î ¸î qîlî¸î=îb î#©î)î,Àî.6î3Ñî5Šî9–î;¼îï˜î…î î î ˜î¾îîöî@ î"ãî%:î&}î)¯î.²î4î7ªî:’îïdîîgî îNîäî| î~îÞî"[î%uî'ê î0<ÿ K « H«b#fSECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS11<== not foundDSend RFAo Store CK, etcDecrypt call pktInvoketDo callagain!lcall send call pktIntruder Wait for ackDsuppress Retransmitc Wait for ackDsuppress Retransmitc Wait for ackDRPC+StubuUserSCaller machine Respond and so on ... Retransmitcsuppress Wait for ackDsuppressallowallowallowallow Call[...] Call[...] Call[...] Call[...] Call[...] Result[...] Result[...]RFA[...].RFA[...]. Reply[...]] Reply[...]] Call[...]<==<< Lookup ConvID Wait for pktDwî œï]:xî cï]:î ï]:wîÃï]:xîÁï]: wîèï]:xîï]:wîPï]:xî Yï]:wî$Ýï]:xî%®ï]:wî,¥ï]:xî-¢ï]:tî;"ï]:rîï!n1}îÂï:î rîËï:î *îÏîÞîîVîîî Ü î':î*Qî,–î0šî4 î6r îï îLî øî õî[î–îîî+î‰î.î"Œî&Hî(� î.mî/Ëî1ýî30î8žîïÑî î`îÊî yîïSî�îXîwîÂïîî$îbî;îhîÈî·î"¬î(]î+cî-ûî2)î5.î7îïÓî î kî’î{îÓ î§îÐî˜î% î'¥î) î+)î.‰î2:î5 î; îï žîáxîŠï žîoï žwî¸ï žîÿ îEîIîÇîáî1î%cî(Dî-Aî1æî5xî8„î:¨îï j î Ü î³î]îoî"î!>î% î(>î,‹ î3L î:|îï 5îî î î îêîêî‘ î¾î!¿î'¡î*øî04î3€î6'î;zîï îªî ’î`î–îßîZîåî! î#(î%§î*Ý î4Iî68 îïÍ î@î îÈ î4î|îOî"eî$�î&Éî,Þî/¡î1½î4]î6Çîï˜î î âî ¾î*îqîìîX î!çî#­î%ªî)£î/ î3Pî5,î6çî:¨îïdîÛ î Ðî‡ îŽîYîzî �î# î$íî(}î*&î/8î0]î3Üî5 î8›î:Ôò « åH«c?ÚÿìÿûÿìJ–ÿîÿïÿü%KÿìòJ–‹.³6, 'ùúøÿîðÿï)ðÿþ!!ùúøÿûùúøÿî5ðÿïðÿþ!!ùúøÿî5ðÿï'ðÿþ!!ùúøÿî5ðÿï#ðÿþ!!ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿîðÿïðÿþ!!ùúøÿûùúøÿûùúøÿîðÿïðÿþ * ùúøÿîÿáÿï/àÿþ?@ùúøÿûùúøÿûùúøÿûùúøÿûùúøÿîðÿïðÿþ * ùúøÿîÿáÿïÿáÿþ??ùúøÿî ðÿïðÿþ * ùúøÿîðÿïðÿþ ùúøÿîðÿïðÿþ * ùúøÿîðÿï+ðÿþ ùúøÿî ðÿïðÿþ ùúøÿîÿáÿïÿáÿþ?0?ùúøÿîàÿï+àÿþAAùúøÿîàÿïÿàÿþAAùúøÿî ðÿï+ðÿþ ùúøÿî?àÿïÿáÿþ@0?ùúøÿî+ðÿï+ðÿþ ùúøÿî+ðÿïðÿþ * ùúøÿî+ðÿïðÿþ ùúøÿî5ðÿïðÿþ * ùúøÿî7ðÿïðÿþ ùúøÿî7ðÿïðÿþ * ùúøÿî7ðÿï+ðÿþ ùúøÿî+àÿï+àÿþAAùúøÿî+àÿï/àÿþ@@ùúøÿî=ðÿïðÿþ * ùúøÿî+àÿïÿáÿþ@?ùúøÿî+àÿïÿàÿþAAùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿûùúøÿîðÿïðÿþ * ùúøÿî#ðÿïðÿþ * ùúøÿîàÿï+àÿþAAùúøÿîàÿï/àÿþAAùúøÿî#àÿï+àÿþAAùúøÿî#àÿïÿàÿþAAùúøÿîàÿïÿàÿþAAùúøÿîàÿïÿàÿþAAùúøÿîðÿï)ðÿþ!!ùúøÿî#ðÿï)ðÿþ!!ùúøÿî#ðÿï#ðÿþ!!ùúøÿîðÿï!ðÿþ!!ùúøÿî#ðÿïðÿþ!!ùúøÿîðÿïðÿþ!!ùúøÿîðÿïðÿþ!!ùúøÿî#ðÿïðÿþ!!ùúøÿî#ðÿï ðÿþ!!ùúøÿîðÿï ðÿþ ùúøÿîðÿïðÿþ!!ùúøÿî#ðÿïðÿþ!!ùúøÿîðÿï ðÿþ!!ÿò™ÿNˆÀ ‹-³@ 0 ·ùúøsî8€ ï*„ðùúøsî8  ï&„ðÿ ùúøsî.€ ï0„ðÿ ùúøsî0€ ï4„ðÿ ùúøsî8à ï0dðÿ ùúøsî/ ï,„ðùúøsî/€ ï*„ðÿ ùúøsî,à ï&„ð ùúøsî-  ï$„ð ÿ ùúøsî.@ ï „ð ÿ ùúøsî-€ ï„ð ÿ ùúøsî-  ï„ð ùúøsî-` ïdð ùúøsî, ï„ð ùúøsî-` ï„ð ÿ ùúøsî.` ï„ðÿ ùúøsî-` ï „ð ùúøsî, ï„ðÿ ùúøsî/€ ï„ðÿ ùúøsî8` ï„ðùúøsî8  ïäðÿ ùúøsîÀ ï,„ðÿ ùúøsî € ï,„ð ùúøsî ï4„ðÿ ùúøsî   ï"„ð ÿ ùúøsî ï&„ðÿ ùúøsî ` ï„ð ÿ ùúøsî   ï„ð ÿ ùúøsî ï$„ðÿ ùúøsî ` ï„ð ÿ ùúøsî   ï„ð ÿ ùúøsî ï0„ðÿ ùúøsî@ ï0dðÿ ùúøsî  ï4„ðÿ ùúøsî À ï „ðùúøsî À ï„ð ùúøsî ` ï$„ð ÿ ùúøsî ï „ðÿ ùúøsî   ï*„ð ÿ ùúøsî ï„ðÿ ùúøsî ï,„ðùúøsî ï„ðùúøsî ï„ðùúøsî ï „ðùúøsî  ï-Dð ùúøsî& ï-¤ð ùúøsî  ï%Dð ùúøsî€ ï$ð ùúøsîÀ ïDð ùúøsî%` ï'¤ð ùúøsî%€ ï!¤ð ùúøsî%À ï¤ðÿ ùúøsî` ï„ðÿ ùúøsî` ï „ð ÿ ùúøsî$  ï „ð ÿ ùúøsî%À ï¤ð ùúøsî ïdñùúøsî ï „ð ùúøsî ` ï„ð ÿ RH„ «*ï=€C$12SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLSmachineidentifier,4bytesfortheconversationidentifier,4bytesforthecallsequencenumber,2bytesfortheprocessidentifierinthecleartextplusanother2intheciphertext.Thisaddssignificantlytotheminimumpackettransmissiontimeandtothetimerequiredtoconstructorinterpretthepacket.Wecouldperformadequateduplicateeliminationfornon-securecallsbyusinga2bytemachineidentifier,2bytecallsequencenumberand2byteprocessidentifier.Thesizecouldbereducedsignificantlybymoresubtleencodings,butonlyatthecostofprocessingtimeininterpretingandverifyingit.Wealsomustmaintainandlook-upthetableintheservergivinginformationabouteachconversation.ThepacketexchangeoftheRFAmechanismisrequiredsolelyforsecurecalls.Oneunexpected(thoughobviousinretrospect)sideeffectofencryptingourpacketswastomakedebuggingourprotocolmoredifficult.AcommonwayofdebuggingEthernetprotocolswithoutperturbingthemistoobservepacketsintransitusingathirdmachine-thisislesseasywhenthepacketsareencryptedwithasecurelygeneratedconversationkey.Wearenotunhappyaboutthesecosts,though.Thecostofsecurityisnotveryhigh,andwearehappytopayitinordertogetawayfromourpreviouscompletelyunprotectedstate.Ofcourse,thereisnoneedforallclientstopaythecostofsecurity.Thosemakingnon-securecallscanhappilyusethesimplerprotocolwedescribedintheearlierpaper[3].Wealsoofferanintermediatestylewhichusessecureauthentication,butdoesnotencryptthecallsthemselves.8.AdditionalDetailsoftheSecurityProtocolCryptologistsareawarethatacipherisoftenmoreeasilybrokeniftheciphertextforknownplaintextisavailable,oriflargeamountsofciphertextareavailableencryptedwithasinglekey.WithDESitisnotclearhowimportantthesethreatsare,butsincethepreventativemeasuresarequitesimplewehaveincludedtheminoursecurityprotocols.Similarly,theinitializationvectorusedbytheCBCmodeofDESmustberandomlychosenandsecurelydistributedifthefirstplaintextblockisknownorhasonlyasmallamountofunknowninformation.Someencryptionhardwareencouragesastyleofusagewheretheprincipal'sprivatekeyisloadedintotheunitonlyonce(possiblymanually),andencryptionisalwaysbyworkingkeys,whicharepresentedtotheunitencryptedwiththeprivatekey;theworkingkeysandtheprivatekeyneedneveroccuroutsidetheencryptionhardwareasplaintext.Inthefollowing,KXandKYaretemporarykeysandJisaninitializationvector,randomlychosenbytheauthenticationservice.Theauthenticatorisinfact:{KX}KB{{CK}KB,T,A}KXThisCBCencryptionusesazeroinitializationvector;itisimportantthat{CK}KBisthefirstplaintextblock,sincethisvalueisunknowntoanintruder.WhentheauthenticationserviceissendingtheauthenticatorbacktoA,itactuallysends:{KY}KA{J,authenticator,X+1,B,CK}KYThisCBCencryptionusesazeroinitializationvector;itisimportantthatJisthefirstplaintexttîï\wî (ï\xî ïï\î ¨ï\wîPï\xîMï\ wîuï\xî“ï\wî Ýï\xî!æï\wî&iï\xî';ï\wî.1ï\xî//ï\wîïT(î™ î ÷î @îèî9î¬ î¸ î$î%_î)î+Xî-Ìî0jî6fî;ÿîïQôîØîXîûî îHî9îÜîqîlî"¨î'÷î)oî+`î.î2€î6šî9÷îïO¿ îáî Åî Zîåîu î�î"èî%Ôî'¸î*Mî-¨î3mî5Qî;oîïM‹îšîìî î‡îFî‘îbî$I î+yî-ª î4˜î7›î9ŠîïKVîGî™îÆî h îÐî"îOî÷îüî$Fî'î(lî+™î0Š î7“î:ˆîïI"îÕîÎî  îÏîÓîoî† î#Rî%Üî(ÿî* î-î/ßî1  î8Wî;…îïFí î«î Žî~îî»î²îEî"+î%î*Yî,ãî0vî2Oî4Úî9îïD¹ î‚î [îƒ îFîîhî$]î& xî(dïD¹î)7ïD¹wî+@ïD¹î2iî3Ìî9SîïB„î>îwîÂï@Pîõ î oîËîîø î øî#ÿî'úî)â î0áî3›î8ªî;…îï>îðî åî ¬îUî$ î¯îwî%bî(vî*jî1_î7Aîï;çîû î ºî2îŒî)î"îðî�î!¶î%Nî&fî)½î/1î0î2­î4î6Œî9~îï9²î`î?î “îõîî9î‡îÒ î'ËîÂï7}îZî¼î ?î îùî‘îIî ôî#Úî&¶î(}î-¡î/î1žî4»î8Gî; îï5IîJîoîî «î ÷î ›îFîëî*î�îúî{î$ î*ò î2‹î6„î8Œîï3îxîÓîÇî î ?îîPîíî}îËî‡î/î"þî'î+Ü î2Æî5Äî8>îï0àî‚îïî åîaî•îÍîˆîõî Eî$4î'%î)¼î,–î/ÿî1ü î:îï.¬îîî Aî’îîCî¸î!®î$ î' yîï)-î� î/î ëî™î÷îewîÂï%á î %î Šî“îsî¯îûîyîî"Äî& î+dî,×î/Hî3”î6^î8­îï#­î�îYîÖ î ûîÑîCî¼î]î'î sî#<î%¡î+nî1âî5î6Iî:Fîï!xxî�ï!xîƒï!xwî~ï!xîóî ~î î‚î¥î%îÍî!hî$3î&Óî*dî,â î4Ïî:àîïDî­î6î �î ëî´îaî3îáî! î(0 î.‡î1 î9îïîPî_xîÒïî�ïwî ¹ïî¢xîoïîTïwîEïîÀîÄî î#²î&|î+Ý î2ãî4Wî6Êî9¶îïÛî¤îOî¦î î Çî(î-îBîÌîÂîgî$f î,£î0d î7*îï§ îKî®î î îî_îø îÔî$ªî'yî)î-Óî0äî3}î6šî9íîïrîþ î îó îî©îEzîyïrî `ïrî$êwî'uïrî(‰ïrî,Ïî/Zî5Òî7¸î:Oîï>îbî }î Üîyî îkîÂîÛî!’î#òî(Žî+#î.€î2Jî6 î:Ôîï îðî îÑîdî!îîz tî!“ï î"†ï wî$ï tî&Óï î'Åï wî)Qï î+ºî2rî5¡tî8mï wî9Âï î;CîïÕ îãî ^î’î$î î î$xîÂï  îš î íîYîtîŠï krîÅï øtîÍï kîrîSï øtî ×ï kî!¿î#ƒî$úrî%ªï øwîï 6xî'ï 6îòï 6wîï 6 î îîôî*î: î)î!cî"Æî$>î*¬tî-‡ï 6î.7ï 6rî0Øï Äwî2íï 6î4eî6Ñî9¶îïîÆîìî lî îÒîLîmî)î'î"wî&�î) î2î6¤î8îïÎî` î ³î útî¨ïÎwî›ïÎîxîÎîätîQï™rî—ï&tî ï™îÕîx î!åî%Ûî'µî*)rî*Úï&wîïdxî:ïdîïdwî-ïd î 'î@î‰î¬ î®î"î#ƒî%î+�tî.}ïdwî/Ýïdî1hî3çî6Þî:| x « H«bSECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS13block,sincethisvalueisunknowntoanintruder.ThepacketreturnedinresponsetoanRFApacketactuallycontains:[B,{J,call-identifier,Y+1}CK,authenticator]Again,theCBCencryptionusesazeroinitializationvector.Whenencryptingpacketsincallsinthisconversation,Jisusedastheinitializationvector.RememberthatallencryptionsotherthanencryptedkeysuseCBCmodewithanadditionalchecksumtodetectmodifications.9.StatusandConclusionsOurremoteprocedurecallpackageisfullyimplementedandisindailyusebyanumberofapplications.TheprotocolforaccessingtheAlpinefileservers(whichprovideafilesystemfeaturingdistributedatomictransactions)usesoursecurityfeatures,asdoesthecontrolprotocolforanethernet-basedvoiceproject.Bothoftheseapplicationshavefoundthesecuritymechanismsentirelypainlesstouse.Unfortunatelythepresentimplementationhastwodeficienciesin.First,mostofourcomputersarenotyetequippedwithDEShardware,soatpresentweareusingatrivialexclusive-orschemeinplaceofagenuineencryption.Second,wehavenotyetretrofittedtheGrapevineserverstosupportthesecureauthenticationprotocol.Weareconfidentthatneitherofthesechangeswouldseriouslydisturbourimplementation,buttheydomakeitimpossibleforustomeasuretheperformanceimpactofencryption.Wearehappywithourdecisiontoincludesecurecommunicationinthispackage.Ithasenabledustoexploreindetailtheimplicationsofourprevioustheoreticaldesignsforsecurecommunication.Ithasshownthatsecurecommunicationcanbesuccessfullyincludedinourprotocolfamily,andthatsecuritycanbepresentedtoprogrammersasacommunicationfacilitythatiseasyandconvenienttouse.Oncewehavesuitablehardwareinplace,wewillrapidlybeabletoconverttoasituationwherewearerelyingonlyonthephysicalsecurityoftheGrapevineserversandoftheparticipatingendusers'workstations.References1.Bauer,K.R.,Berson,T.A.andFeiertag,R.J.Akeydistributionprotocolusingeventmarkers.SytekreportTR-81060,SytekInc.,Sunnyvale,CA,1981.2.Birrell,A.D.,Levin,R.,Needham,R.M.andSchroeder,M.D.Grapevine:anexerciseindistributedcomputing.Comm.ACM25,4(April1982),260-274.3.Birrell,A.DandNelson,B.J.ImplementingRemoteProcedureCalls.Trans.OnComp.Sys.2,1(February1984),??-??.4.DataEncryptionStandard.FIPSpublication46,NationalBureauofStandards,U.S.DepartmentofCommerce,WashingtonD.C.January1977.5.Denning,D.E.andSacco,G.M.Timestampsinkeydistributionprotocols.Comm.ACM24,8wî œï]'xî cï]'î ï]'wîÃï]'xîÁï]' wîèï]'xîï]'wîPï]'xî Yï]'wî$Ýï]'xî%®ï]'wî,¥ï]'xî-¢ï]'tî;"ï]'wîïU7î îpî î  îþîî¤î‡î î!kî%¸î+Fî,æî2}î4xî6ïU7î6ÕïU7wî8ØïU7îïSîtîÂïPÎî¿î™îÎîqî§î!Frî!öïQ[tî#ƒïPÎî$j î-twîïNšîcxîÁïNšîŒïNšwî ’ïNš îkîcî‹î� înî$iî(€ î/Nî4,î5Øî8åî:’îïLe tî›ïLewî %ïLeî ÛîaîYî î/î!Âî))î,Aî.{ î6$î: îïJ1îbî |xî ñïJ1î ¼ïJ1wîÄïJ1îšîµî¥ îî$sî&"î*0 yîïD³î�îÜî| wîÂïAgîÃî ‰î*îÔî4î¾î î&ˆî)^î*èî,´î0:î2Íî4çî60î;zîï?3 îOî îsîŸîuîÃî7î!�î&î*„î/}î0•î2íî7Wîï<þ îDî  î[î¦î‚îêî%¿î'¿î+@î-ñî2õî8´î;Cîï:Ê î +î ¯î îVîîz î"î%7î)5î+…î0Œ î84îï8•î,îÚîÂï6a î ¤î ùîà î˜îî!¤ î(ùî+nî/î2Uî4î6„îï4,îWîÏîî 4xîRï4,î7ï4,wîï4,î{îCîÞî!¶î#àî&7î)äî+î/ î6£î;…îï1øî�î>î`î � î7î[î{îºî 'î"i î(äî+<î1øî6�î8'îï/Äîjî® î°îî£îî!*î$î(¿î*‚î.î3Kî7„îï-�îæî¤î îÀîî;î"îª î&«î)î+î,ýî2�î5/ îï+[îˆîA îÂï)&î3îmî ‚îƒîõî3îÈîŽî ® î*Gî+Ûî.cî4Nî5¬î8îï&òîÄîgîDî æî ¦îù î¤îRîÑî!T î(î,Êî.ûî3) îï$½î—î+îšî ‡îà î²î]îm î%öî+¼î-‰î03î5Áî:|îï"‰îµî±î #î ùî î´ îî•î¥ î(>î,ªî/_î0°î3šî68 îï Tî¼î&îÑî îYî|î’îMîFî!zî$2î(ñî*ïî-õî/°î4§î6bî7˜îï îî=î�î *îBîGî¥îñîî ¾î#î)Þî.mî1#î2Ûî59 îïìî¸îŽ yîïn wîï"î¶î:î î6î‚îcîGîHîþî"½ î*Qî/éî3¼î7›zî¿ïîî˜î �wîaïîî=ïîîî" î)î" îïsîpîîî „î «îËîUîÊîd î#"î&® î-Îî/¡î4°î6A î¿ï > zî vï >î tï >î-îwîaï >î>ï >îsîŠî¡îï Ãî‡îî î ÊîÓî�î îÛî"î(ˆzî,Êï Ãî-²ï Ãî1î3Pî7›î:xwî;(ï Ãî;ÿï Ãî¿ï�î 6î Nîïî‰îã î ýzî°ïîŒïîl î^wî¿ïî˜ïî%>î*î+¹ î2pî5† î¿ïßîxî Ë îlî¼îèîïdî¨îÌî !î ôîIî îßî¨î"Y î)ß zî0äïdî1âïdî5¶î9¦wî;ïdî;ÿïdÿ  « øH«c,14SECURECOMMUNICATIONUSINGREMOTEPROCEDURECALLS(August1981),533-536.6.DESmodesofoperation.FIPSpublication81,NationalBureauofStandards,U.S.DepartmentofCommerce,WashingtonD.C.December1980.7.Ehrsam,W.F.,Matyas,S.M.,Meyer,C.H.,Tuchman,W.L.Acryptographickeymanagementschemeforimplementingthedataencryptionstandard.IBMSyst.J.17,2(1978),106-125.8.Kline,C.S.andPopek,G.J.Publickeyvs.conventionalkeyencryption.AFIPSConferenceProceedings48,1979,831-837.9.Matyas,S.M.andMeyer,C.H.Generation,distributionandinstallationofcryptographickeys.IBMSyst.J.17,2(1978),126-137.10.Needham,R.M.andSchroeder,M.D.Usingencryptionforauthenticationinlargenetworksofcomputers.Comm.ACM21,12(December1978),993-999.11.Voydock,V.L.andKent,S.T.Securityinhigherlevelprotocols:approaches,alternativesandrecommendations.BBNReport4767,BoltBeranekandNewman,Inc.,(October1981).AlsoavailableasReportICST/HLNP-81-19,NationalBureauofStandards,WashingtonD.C.(October1981).12.Voydock,V.L.andKent,S.T.SecurityMechanismsinHigh-LevelNetworkProtocolsACMComp.Surveys15,2(June1983).tîï-‘wî (ï-‘xî ïï-‘î ¨ï-‘wîPï-‘xîMï-‘ wîuï-‘xî“ï-‘wî Ýï-‘xî!æï-‘wî&iï-‘xî';ï-‘wî.1ï-‘xî//ï-‘wî¿ï%™î÷î îï#î˜îõî [î  zî;ï#îï#î îwîhï#îOï#î%î)Øî+œ î2bî5† î¿ï éîxî Ë îlî¼î`îïnîÀîVî ]î±îŒîrîNî$î'²î)r î2Pî5 î¿ï:îžî Ü î›îûî îÚzî%Qï:î%ìï:î(¸î, î-‚wî.ãï:î/¿ï:î0ôî5…îï¿îÆî/î `î QîîLîËîšîã î&7î) zî1/ï¿î2,ï¿î6% î¿ïŠ î 7wî ˜ïŠî tïŠîîïîµîÿî xî Xî2î¬ îj î$þî'Þ î/ î0î î9Âzî¿ïÛî&î yî ðwî QïÛî .ïÛîbîóîï`îLî î ¤îk îUî î î%î'T î0[î2î5�î;zî¿ï+ zî Jï+î Hï+îîÕwî5ï+îï+î÷îî"+îï °îaî£î ßîºî¶î»î8î î!}î$ç î+v î3 î:|î¿ï |zîÍï |îÀï |î_îæwî¨ï |î™ï |î¦î#î%éî,6î/dî5@î:î¿ïHîNzî ÐïHî ÎïHîwîïïHîŸïHî î$¹î&F î,Ô î4Hî7lî¿ïîï˜îgî¯î ñîÒîÓîÞîa î#nî%E î,­î2Šzî9_ï˜î:]ï˜î¿ïdîî wî rïdîOïdîƒîOÿ «9ŽH«3–ÿÿ HELVETICAý…ÿ HELVETICAþYÿ HELVETICAþæÿ HELVETICAþŸÿ HELVETICAþŸÿLOGOü´ÿ HELVETICAþÿ TIMESROMANþŸÿ TIMESROMANþæ ÿ TIMESROMANþŸ ÿ TIMESROMANþŸ ÿ TIMESROMANþæ ÿ HELVETICAþŸ ÿ HELVETICAþæÿ HELVETICAþæÿ TIMESROMAN ÿ HELVETICA � ¹ 1 ‘' î3 d= ‹H¸d;Ÿ Jª s¶2Ûè ¦ó aüý ;Û1 ÿÿÿÿwÃlif`C.S. andd-ekmf`mwÃwÃc key vs. dr ¸en �#d=ion. AFRPCSecurityPaper.cm.indV 48, 1h=wÂhAwö-837. d\9.dfdeñdmdeê�dÃdŸf@dádpdqñd|dqê�dÏd«fLdí8üdÃdšdˆóŽê�d«¼ntdÏd«d«dídºÖ½“düôiôŒê�fPfK½‡Ö½“ÖôŒ½—d«däÖdäóÖê�dϼnt½‡ÖNê�fKôŒu½—óÖd¸dÏj/ÿÿœXÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿRPCSecurityPaper.press Birrell.pat13-Feb-84 15:07:02 PST: