Search papers, labs, and topics across Lattice.
This paper introduces the concept of a rational Dolev鈥揧ao attacker, which models network intruders as utility-maximizing agents whose actions are influenced by associated costs and rewards. The authors establish a framework for verifying the rational security of protocols using a weighted fragment of Alternating-time Temporal Logic (WATL), proving decidability for bounded rational attackers in finite cost-annotated concurrent game structures. Key findings reveal that some protocols can be insecure under traditional Dolev鈥揧ao assumptions while remaining rationally secure, highlighting a computable threshold that separates these two security notions.
Some protocols are vulnerable to traditional Dolev鈥揧ao attacks but remain secure against rational attackers, revealing a critical gap in conventional security assessments.
Symbolic protocol verification models the network attacker as a Dolev--Yao (DY) intruder, which does everything its knowledge permits, whether or not it serves any purpose; real adversaries instead maximise utility, attacking only when the payoff is positive. We introduce a rational Dolev--Yao attacker, a DY intruder whose actions carry costs and whose security-violating goals carry rewards, and call a protocol rationally secure when no intruder strategy achieves a violation with strictly positive utility, expressed in a weighted fragment of ATL (WATL). We prove this decidable for a bounded rational DY intruder over a finite cost-annotated concurrent game structure, characterise its complexity, and show it strictly refines DY security: some protocols are DY-insecure yet rationally secure, separated by a computable threshold. We illustrate the framework on two contrasting use-cases: an authenticated payment under session uncertainty, where a rational intruder must strategise across indistinguishable sessions and its imperfect information strictly raises the attack cost a designer must price against; and ThreeBallot, a cryptography-free scheme where we pinpoint the bribe-to-benefit ratio below which no rational coercer attacks.