Needham Schroeder Protocol


Attack - No sender’s information
Version 2

Attack - X has recorded all previous conversations and knows b’s long term secret key

Version 3


Attack - X has previous shared key, is impersonating A
Version 4

| Threat | Is Version 4 Safe? | Why? |
|---|---|---|
| Traditional Replay | Yes | The $R_4$ nonce ensures the ticket was created after the request. |
| Man-in-the-Middle | Yes | The responder's identity is tied to the exchange. |
| Old Key Usage | Partially | Safe against old recordings, but vulnerable during the timestamp "window". |
| Clock Out-of-Sync | No | If clocks drift, the "freshness" guarantee of the timestamp fails. |