The spring semester 2021 will certainly take place online until Easter. Exceptions: Courses that can only be carried out with on-site presence. Please note the information provided by the lecturers.

Sasa Radomirovic: Catalogue data in Spring Semester 2016

Name Dr. Sasa Radomirovic
Tüffenwies 33
8064 Zürich
Telephone077 437 7351
DepartmentComputer Science

263-4600-00LFormal Methods for Information Security Information 4 credits2V + 1UC. Sprenger, S. Radomirovic, R. Sasse
AbstractThe course focuses on formal methods for the modelling and analysis of security protocols for critical systems, ranging from authentication protocols for network security to electronic voting protocols and online banking.
ObjectiveThe students will learn the key ideas and theoretical foundations of formal modelling and analysis of security protocols. The students will complement their theoretical knowledge by solving practical exercises, completing a small project, and using various state-of-the-art tools.
ContentThe course treats formal methods for the modelling and analysis of security protocols. Cryptographic protocols (such as SSL/TLS, SSH, Kerberos, SAML single-sign on, and IPSec) form the basis for secure communication and business processes. Numerous attacks on published protocols show that the design of cryptographic protocols is extremely error-prone. A rigorous analysis of these protocols is therefore indispensable, and manual analysis is insufficient. The lectures cover the theoretical basis for the (tool-supported) formal modeling and analysis of such protocols. Specifically, we discuss their operational semantics, the formalization of security properties, and techniques and algorithms for their verification.

In addition to the classical security properties for confidentiality and authentication, we will study strong secrecy, privacy, and fairness properties. We will discuss electronic voting protocols, RFID protocols (a staple of the Internet of Things), and contract signing protocols where these properties are central. The accompanying tutorials provide an opportunity to apply the theory and tools to concrete protocols.