{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T13:03:09Z","timestamp":1784638989410,"version":"3.55.0"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031171420","type":"print"},{"value":"9783031171437","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-17143-7_4","type":"book-chapter","created":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T04:04:22Z","timestamp":1663905862000},"page":"63-83","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["A Tale of\u00a0Two Models: Formal Verification of\u00a0KEMTLS via\u00a0Tamarin"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3333-7764","authenticated-orcid":false,"given":"Sof\u00eda","family":"Celi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9810-0330","authenticated-orcid":false,"given":"Jonathan","family":"Hoyland","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9443-3170","authenticated-orcid":false,"given":"Douglas","family":"Stebila","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8967-8456","authenticated-orcid":false,"given":"Thom","family":"Wiggers","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,24]]},"reference":[{"key":"4_CR1","doi-asserted-by":"publisher","unstructured":"Barbosa, M., et al.: SoK: computer-aided cryptography. In: 2021 IEEE Symposium on Security and Privacy, pp. 777\u2013795. IEEE Computer Society Press (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00008","DOI":"10.1109\/SP40001.2021.00008"},{"key":"4_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-642-22792-9_5","volume-title":"Advances in Cryptology \u2013 CRYPTO 2011","author":"G Barthe","year":"2011","unstructured":"Barthe, G., Gr\u00e9goire, B., Heraud, S., B\u00e9guelin, S.Z.: Computer-aided security proofs for the working cryptographer. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 71\u201390. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22792-9_5"},{"key":"4_CR3","unstructured":"Basin, D., Cremers, C., Dreier, J., Meier, S., Sasse, R., Schmidt, B.: Tamarin prover (2022). https:\/\/tamarin-prover.github.io"},{"key":"4_CR4","doi-asserted-by":"publisher","unstructured":"Basin, D.A., Dreier, J., Sasse, R.: Automated symbolic proofs of observational equivalence. In: Ray, I., Li, N., Kruegel, C. (eds.) ACM CCS 2015, pp. 1144\u20131155. ACM Press (2015). https:\/\/doi.org\/10.1145\/2810103.2813662","DOI":"10.1145\/2810103.2813662"},{"key":"4_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1007\/BFb0030423","volume-title":"Information Security","author":"M Bellare","year":"1998","unstructured":"Bellare, M.: Practice-oriented provable-security. In: Okamoto, E., Davida, G., Mambo, M. (eds.) ISW 1997. LNCS, vol. 1396, pp. 221\u2013231. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0030423"},{"key":"4_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1007\/3-540-48329-2_21","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 93","author":"M Bellare","year":"1994","unstructured":"Bellare, M., Rogaway, P.: Entity authentication and key distribution. In: Stinson, D.R. (ed.) CRYPTO 1993. LNCS, vol. 773, pp. 232\u2013249. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48329-2_21"},{"key":"4_CR7","doi-asserted-by":"publisher","unstructured":"Bhargavan, K., Blanchet, B., Kobeissi, N.: Verified models and reference implementations for the TLS 1.3 standard candidate. In: 2017 IEEE Symposium on Security and Privacy, pp. 483\u2013502. IEEE Computer Society Press (2017). https:\/\/doi.org\/10.1109\/SP.2017.26","DOI":"10.1109\/SP.2017.26"},{"key":"4_CR8","unstructured":"Bhargavan, K., Cheval, V., Wood, C.: Handshake privacy for TLS 1.3 - technical report. Research report, Inria Paris, Cloudflare (2022). https:\/\/hal.inria.fr\/hal-03594482"},{"key":"4_CR9","unstructured":"Blanchet, B.: An efficient cryptographic protocol verifier based on Prolog rules. In: 14th IEEE Computer Security Foundations Workshop (CSFW-14), pp. 82\u201396. IEEE Computer Society (2001)"},{"key":"4_CR10","doi-asserted-by":"publisher","unstructured":"Boyd, C., Mathuria, A., Stebila, D.: Protocols for Authentication and Key Establishment. Springer, Heidelberg (2019). https:\/\/doi.org\/10.1007\/978-3-662-58146-9","DOI":"10.1007\/978-3-662-58146-9"},{"key":"4_CR11","unstructured":"Brzuska, C.: On the Foundations of Key Exchange, Ph.D. thesis, Technische Universit\u00e4t Darmstadt (2013). http:\/\/tuprints.ulb.tu-darmstadt.de\/3414\/"},{"key":"4_CR12","doi-asserted-by":"publisher","unstructured":"Brzuska, C., Fischlin, M., Warinschi, B., Williams, S.C.: Composability of Bellare-Rogaway key exchange protocols. In: Chen, Y., Danezis, G., Shmatikov, V. (eds.) ACM CCS 2011, pp. 51\u201362. ACM Press (2011). https:\/\/doi.org\/10.1145\/2046707.2046716","DOI":"10.1145\/2046707.2046716"},{"key":"4_CR13","unstructured":"Celi, S., Schwabe, P., Stebila, D., Sullivan, N., Wiggers, T.: KEM-based Authentication for TLS 1.3. Internet-Draft draft-celi-wiggers-tls-authkem-01, Internet Engineering Task Force (2022). https:\/\/datatracker.ietf.org\/doc\/html\/draft-celi-wiggers-tls-authkem-01, Work in Progress"},{"key":"4_CR14","doi-asserted-by":"publisher","unstructured":"Cremers, C., Horvat, M., Hoyland, J., Scott, S., van der Merwe, T.: A comprehensive symbolic analysis of TLS 1.3. In: Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017, pp. 1773\u20131788. ACM Press (2017). https:\/\/doi.org\/10.1145\/3133956.3134063","DOI":"10.1145\/3133956.3134063"},{"key":"4_CR15","doi-asserted-by":"publisher","unstructured":"Cremers, C., Horvat, M., Scott, S., van der Merwe, T.: Automated analysis and verification of TLS 1.3: 0-RTT, resumption and delayed authentication. In: 2016 IEEE Symposium on Security and Privacy, pp. 470\u2013485. IEEE Computer Society Press (2016). https:\/\/doi.org\/10.1109\/SP.2016.35","DOI":"10.1109\/SP.2016.35"},{"key":"4_CR16","doi-asserted-by":"publisher","unstructured":"Delignat-Lavaud, A., et al.: Implementing and proving the TLS 1.3 record layer. In: 2017 IEEE Symposium on Security and Privacy, pp. 463\u2013482. IEEE Computer Society Press (2017). https:\/\/doi.org\/10.1109\/SP.2017.58","DOI":"10.1109\/SP.2017.58"},{"key":"4_CR17","doi-asserted-by":"publisher","unstructured":"Di Raimondo, M., Gennaro, R., Krawczyk, H.: Deniable authentication and key exchange. In: Juels, A., Wright, R.N., De Capitani di Vimercati, S. (eds.) ACM CCS 2006, pp. 400\u2013409. ACM Press (2006). https:\/\/doi.org\/10.1145\/1180405.1180454","DOI":"10.1145\/1180405.1180454"},{"key":"4_CR18","doi-asserted-by":"publisher","unstructured":"Dolev, D., Yao, A.C.C.: On the security of public key protocols (extended abstract). In: 22nd FOCS, pp. 350\u2013357. IEEE Computer Society Press (1981). https:\/\/doi.org\/10.1109\/SFCS.1981.32","DOI":"10.1109\/SFCS.1981.32"},{"key":"4_CR19","doi-asserted-by":"publisher","unstructured":"Dowling, B., Fischlin, M., G\u00fcnther, F., Stebila, D.: A cryptographic analysis of the TLS 1.3 handshake protocol candidates. In: Ray, I., Li, N., Kruegel, C. (eds.) ACM CCS 2015, pp. 1197\u20131210. ACM Press (2015). https:\/\/doi.org\/10.1145\/2810103.2813653","DOI":"10.1145\/2810103.2813653"},{"issue":"4","key":"4_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s00145-021-09384-1","volume":"34","author":"B Dowling","year":"2021","unstructured":"Dowling, B., Fischlin, M., G\u00fcnther, F., Stebila, D.: A cryptographic analysis of the TLS 1.3 handshake protocol. J. Cryptol. 34(4), 1\u201369 (2021). https:\/\/doi.org\/10.1007\/s00145-021-09384-1","journal-title":"J. Cryptol."},{"key":"4_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"270","DOI":"10.1007\/978-3-319-19962-7_16","volume-title":"Information Security and Privacy","author":"B Dowling","year":"2015","unstructured":"Dowling, B., Stebila, D.: Modelling Ciphersuite and version negotiation in the TLS protocol. In: Foo, E., Stebila, D. (eds.) ACISP 2015. LNCS, vol. 9144, pp. 270\u2013288. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-19962-7_16"},{"issue":"3","key":"4_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s00145-021-09387-y","volume":"34","author":"N Drucker","year":"2021","unstructured":"Drucker, N., Gueron, S.: Selfie: reflections on TLS 1.3 with PSK. J. Cryptol. 34(3), 1\u201318 (2021). https:\/\/doi.org\/10.1007\/s00145-021-09387-y","journal-title":"J. Cryptol."},{"key":"4_CR23","doi-asserted-by":"publisher","unstructured":"Dwork, C., Naor, M., Sahai, A.: Concurrent zero-knowledge. In: 30th ACM STOC, pp. 409\u2013418. ACM Press (1998). https:\/\/doi.org\/10.1145\/276698.276853","DOI":"10.1145\/276698.276853"},{"key":"4_CR24","doi-asserted-by":"publisher","unstructured":"Fischlin, M., G\u00fcnther, F.: Multi-stage key exchange and the case of Google\u2019s QUIC protocol. In: Ahn, G.J., Yung, M., Li, N. (eds.) ACM CCS 2014, pp. 1193\u20131204. ACM Press (2014). https:\/\/doi.org\/10.1145\/2660267.2660308","DOI":"10.1145\/2660267.2660308"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"G\u00fcnther, F., Rastikian, S., Towa, P., Wiggers, T.: KEMTLS with delayed forward identity protection in (Almost) a single round trip. In: ACNS 2022 (2022). https:\/\/eprint.iacr.org\/2021\/725","DOI":"10.1007\/978-3-031-09234-3_13"},{"key":"4_CR26","doi-asserted-by":"publisher","unstructured":"H\u00fclsing, A., Weber, F.: Epochal signatures for deniable group chats. In: 2021 IEEE Symposium on Security and Privacy, pp. 1677\u20131695. IEEE Computer Society Press (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00058","DOI":"10.1109\/SP40001.2021.00058"},{"key":"4_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1007\/978-3-319-26617-6_5","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2015","author":"M Kohlweiss","year":"2015","unstructured":"Kohlweiss, M., Maurer, U., Onete, C., Tackmann, B., Venturi, D.: (De-)Constructing TLS 1.3. In: Biryukov, A., Goyal, V. (eds.) INDOCRYPT 2015. LNCS, vol. 9462, pp. 85\u2013102. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-26617-6_5"},{"key":"4_CR28","doi-asserted-by":"publisher","unstructured":"Krawczyk, H., Wee, H.: The OPTLS protocol and TLS 1.3. In: 2016 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 81\u201396 (2016). https:\/\/doi.org\/10.1109\/EuroSP.2016.18","DOI":"10.1109\/EuroSP.2016.18"},{"key":"4_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"696","DOI":"10.1007\/978-3-642-39799-8_48","volume-title":"Computer Aided Verification","author":"S Meier","year":"2013","unstructured":"Meier, S., Schmidt, B., Cremers, C., Basin, D.: The TAMARIN prover for the symbolic analysis of security protocols. In: Sharygina, N., Veith, H. (eds.) CAV 2013. LNCS, vol. 8044, pp. 696\u2013701. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-39799-8_48"},{"key":"4_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"160","DOI":"10.1007\/978-3-319-49100-4_7","volume-title":"Security Standardisation Research","author":"KG Paterson","year":"2016","unstructured":"Paterson, K.G., van der Merwe, T.: Reactive and proactive standardisation of TLS. In: Chen, L., McGrew, D., Mitchell, C. (eds.) SSR 2016. LNCS, vol. 10074, pp. 160\u2013186. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-49100-4_7"},{"key":"4_CR31","doi-asserted-by":"publisher","unstructured":"Rescorla, E.: The Transport Layer Security TLS Protocol Version 1.3. RFC 8446, RFC Editor (2018). https:\/\/doi.org\/10.17487\/RFC8446","DOI":"10.17487\/RFC8446"},{"key":"4_CR32","doi-asserted-by":"publisher","unstructured":"Schwabe, P., Stebila, D., Wiggers, T.: Post-quantum TLS without handshake signatures. In: Ligatti, J., Ou, X., Katz, J., Vigna, G. (eds.) ACM CCS 2020, pp. 1461\u20131480. ACM Press (2020). https:\/\/doi.org\/10.1145\/3372297.3423350","DOI":"10.1145\/3372297.3423350"},{"key":"4_CR33","doi-asserted-by":"crossref","unstructured":"Schwabe, P., Stebila, D., Wiggers, T.: Post-quantum TLS without handshake signatures. Cryptology ePrint Archive, Report 2020\/534 (2020). https:\/\/eprint.iacr.org\/2020\/534","DOI":"10.1145\/3372297.3423350"},{"key":"4_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-88418-5_1","volume-title":"Computer Security \u2013 ESORICS 2021","author":"P Schwabe","year":"2021","unstructured":"Schwabe, P., Stebila, D., Wiggers, T.: More efficient post-quantum KEMTLS with pre-distributed public keys. In: Bertino, E., Shulman, H., Waidner, M. (eds.) ESORICS 2021. LNCS, vol. 12972, pp. 3\u201322. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-88418-5_1"},{"key":"4_CR35","doi-asserted-by":"crossref","unstructured":"Schwabe, P., Stebila, D., Wiggers, T.: More efficient post-quantum KEMTLS with pre-distributed public keys. Cryptology ePrint Archive, Report 2021\/779 (2021). https:\/\/eprint.iacr.org\/2021\/779","DOI":"10.1007\/978-3-030-88418-5_1"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-17143-7_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T04:05:23Z","timestamp":1663905923000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-17143-7_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031171420","9783031171437"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-17143-7_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"24 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"562","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"104","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"12","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}