Skip to content

Needham Schroeder Protocol

Pasted image 20260224165421.png

Pasted image 20260224165401.png

Attack - No sender’s information

Version 2

Pasted image 20260224165547.png

Attack - X has recorded all previous conversations and knows b’s long term secret key Pasted image 20260224181740.png

Version 3

Pasted image 20260224182131.png

Pasted image 20260224182610.png

Attack - X has previous shared key, is impersonating A

Version 4

Pasted image 20260224185054.png

Threat Is Version 4 Safe? Why?
Traditional Replay Yes The $R_4$ nonce ensures the ticket was created after the request.
Man-in-the-Middle Yes The responder's identity is tied to the exchange.
Old Key Usage Partially Safe against old recordings, but vulnerable during the timestamp "window".
Clock Out-of-Sync No If clocks drift, the "freshness" guarantee of the timestamp fails.