Wide Mouth Frog Protocol

The Wide-Mouth Frog protocol is a computer network authentication protocol designed for use on insecure networks (the Internet for example). It allows individuals communicating over a network to prove their identity to each other while also preventing eavesdropping or replay attacks, and provides for detection of modification and the prevention of unauthorized reading. This can be proven using BAN logic.

The protocol was first described under the name "The Wide-mouthed-frog Protocol" in the paper "A Logic of Authentication" (1990), which introduced Burrows–Abadi–Needham logic, and in which it was an "unpublished protocol ... proposed by" coauthor Michael Burrows. The paper gives no rationale for the protocol's whimsical name.

The protocol can be specified as follows in security protocol notation:

  • A, B, and S are identities of Alice, Bob, and the trusted server respectively
  • and are timestamps generated by A and S respectively
  • is a symmetric key known only to A and S
  • is a generated symmetric key, which will be the session key of the session between A and B
  • is a symmetric key known only to B and S

Note that to prevent active attacks, some form of authenticated encryption (or message authentication) must be used.

The protocol has several problems:

  • a global clock is required.
  • the server S has access to all keys.
  • the value of the session key is completely determined by A, who must be competent enough to generate good keys.
  • can replay messages within period when timestamp is valid.
  • A is not assured that B exists.
  • The protocol is stateful. This is usually undesired because it requires more functionality and capability from the server. For example, S must be able to deal with situations in which B is unavailable.

Famous quotes containing the words wide, mouth and/or frog:

    Many have dreamed up republics and principalities that have never in truth been known to exist; the gulf between how one should live and how one does live is so wide that that a man who neglects what is actually done for what should be done learns the way to self-destruction rather than self-preservation.
    Niccolò Machiavelli (1469–1527)

    Dead mountain mouth of carious teeth that cannot spit
    Here one can neither stand nor lie nor sit
    There is not even silence in the mountains
    But dry sterile thunder without rain
    —T.S. (Thomas Stearns)

    What a wonderful bird the frog are—
    When he stand he sit almost;
    When he hop, he fly almost.
    He ain’t got no sense hardly;
    He ain’t got no tail hardly either.
    When he sit, he sit on what he ain’t got almost.
    —Unknown. The Frog (l. 1–6)