• Aucun résultat trouvé

Verifiability in e-Auction protocols & Brandt's protocol revisited

N/A
N/A
Protected

Academic year: 2021

Partager "Verifiability in e-Auction protocols & Brandt's protocol revisited"

Copied!
1
0
0

Texte intégral

(1)

Verifiability in e-Auction Protocols

& Brandt’s Protocol Revisited

Jannik Dreier

Universit´

e Grenoble 1, CNRS, VERIMAG

jannik.dreier@imag.fr

Jean-Guillaume Dumas

Universit´

e Grenoble 1, CNRS, Laboratoire Jean Kuntzmann (LJK)

jean-guillaume.dumas@imag.fr

Hugo Jonker

University of Luxembourg

hugo.jonker@uni.lu

Pascal Lafourcade

Universit´

e Grenoble 1, CNRS, VERIMAG

pascal.lafourcade@imag.fr

February 22, 2013

Abstract

An electronic auction protocol will only be used by those who trust that it operates correctly. Therefore, e-auction protocols must be verifi-able: seller, buyer and losing bidders must all be able to determine that the result was correct. We pose that the importance of verifiability for e-auctions necessitates a formal analysis. Consequently, in the first part of the talk, we identify notions of verifiability for each stakeholder. We formalize these and then use the developed framework to study the ver-ifiability of several examples. We provide an analysis of the protocol by Sako in the applied pi-calculus with help of ProVerif, finding it to be cor-rect. Additionally we identify issues with the protocols due to Curtis et al. and Brandt.

In the second part, we will analyze the protocol by Brandt in more detail. We show first that this protocol – when using malleable interactive zero-knowledge proofs – is vulnerable to attacks by dishonest bidders. Such bidders can manipulate the publicly available data in a way that allows the seller to deduce all participants’ bids. Additionally we discuss attacks on non-repudiation, fairness and the privacy of individual bidders exploiting authentication problems.

Références

Documents relatifs

Thus semantic connection should replace semantic value as the principal object of semantic enquiry; and just as the semantic evaluation of a complex expression is naturally taken

We might additionally require the results of human computation to have high validity or high utility, but the results must be reproducible in order to measure the validity or utility

Dr Fortin thanks the patients and co-investigators of the Saguenay group associated with the Research Chair on Chronic Diseases in Primary Care.. Competing interests None

I think physicians who truly take the time to talk to their patients in depth about weight, using a nonthreat- ening, question-and-answer approach, will be shocked by

Patient versus physician responses to the survey questions about physicians using resources to look up medical questions: Patient participants were asked how their confidence in

• A winning bidder wants to check that: – he actually submitted the winning bid, – the final price is correctly computed, – all other bids originated from bidders, and – no bid

(Je n'ai pas besoin de faire cela.. PETER: 'I'm sorry.. Modaux - verbes défectifs, révisons les pas à pas. Les modaux, ces verbes défectifs. Révisons pas

Devoir may be followed by an infinitive or may stand alone to have the meaning "to have to" (Je doispartir, I must leave.) When followed by a noun, devoir means "to