secure protocol design

Designs, implements, and analyzes secure communication and cryptographic protocols—including authentication, transport, heartbeat, industrial, and hardware-interface protocols—as well as protocol adapters and language-server/networking protocol integrations. Produces protocol specifications and implementations, adapts and optimizes protocols for new environments, and evaluates correctness, security, and performance using formal analysis, testing, and experimental development.

secureprotocoldesign

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-2.63
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$191K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Verification and Attack Synthesis for Network Protocols

Nov 02, 2025
MV
Max von Hippel
🏛️ Northeastern University

Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.

Applying formal methods to analyze protocols under normal and attack conditionsSynthesizing attacks that prevent protocol requirement achievementVerifying network protocol functionality and performance requirements

It Takes a Village: Bridging the Gaps between Current and Formal Specifications for Protocols

Sep 16, 2025
DB
David Basin
🏛️ ETH Zürich | Cornell University | University of Texas, Austin | Nokia Bell Labs | Northeastern University | University of Pennsylvania | Princeton University | University of Illinois Chicago

This work addresses the semantic gap between informal protocol specifications—such as IETF RFCs—and formal specifications. It introduces a cognitive discrepancy analysis framework that identifies fundamental limitations in RFCs, including semantic ambiguity, unstated assumptions, and logical inconsistency. Methodologically, the approach integrates formal specification languages (e.g., TLA⁺), state-machine modeling, and protocol conformance testing to perform semantic parsing and cross-version consistency checking on real-world RFC texts and reference implementations. A key contribution is the establishment of a collaborative paradigm bridging industry practitioners and formal methods researchers, facilitating the evolution of RFCs into verifiable, executable formal specifications. Empirical evaluation demonstrates that this methodology significantly improves defect detection rates, interoperability assurance, and depth of security verification. The proposed framework provides a reusable, scalable foundation for formalizing next-generation Internet protocol standards.

Addressing underuse of formal specifications in Internet standardsBridging gaps between informal and formal protocol specificationsIdentifying benefits of formal methods for network protocols

Validating Network Protocol Parsers with Traceable RFC Document Interpretation

Apr 25, 2025
MZ
Mingwei Zheng
🏛️ Purdue University | Nanjing University

Addressing the “oracle absence” and “error attribution difficulty” challenges in network protocol parser verification, this paper proposes an LLM-driven framework for RFC semantic parsing and feedback-based oracle refinement. First, large language models automatically translate unstructured RFC text into formal message specifications. Second, an iterative, quasi-oracle is constructed to support specification-guided fuzz testing and cross-language (C/Python/Go) protocol implementation verification. Finally, vulnerabilities are precisely traced back to their originating RFC clauses. This work is the first to integrate LLM-based semantic understanding with dynamic oracle refinement. Evaluated on nine mainstream protocols, it discovers 69 vulnerabilities—36 of which have been confirmed—surpassing state-of-the-art approaches in both effectiveness and efficiency. It also demonstrates, for the first time, the feasibility of fully automated derivation of test oracles directly from natural-language protocol specifications.

Addressing oracle and traceability issues in protocol validationAutomating software validation via LLM-based specification translationValidating network protocol parsers using RFC documents

Formal Methods for Mobile Ad Hoc Networks: A Survey

Oct 21, 2025
WF
Wan Fokkink
🏛️ Vrije Universiteit Amsterdam | University of Edinburgh

Existing formal verification approaches for Mobile Ad-hoc Network (MANET) routing protocols lack a unified framework integrating functional correctness, real-time guarantees, and security. Method: This work introduces the first systematic integration of multi-dimensional formal methods: temporal logic and process algebra for specification; model checking and performance modeling for analysis; and a mobility model tailored to MANETs’ dynamic topology. A taxonomy classifying functional, timing, and security properties is proposed, alongside a consolidated survey of modeling paradigms and verification tools, establishing explicit mappings among protocols, formal methods, and property classes. Contribution: The study delivers a reusable theoretical framework and methodological pipeline for formal verification of MANET routing protocols. It bridges a critical gap by providing the first comprehensive, structured survey and foundational framework for this fragmented domain—enabling rigorous, holistic protocol assurance across functional, temporal, and security dimensions.

Providing overview of formal frameworks and mobility modelsReviewing techniques for assessing real-time and security propertiesSurveying formal methods for analyzing MANET protocol correctness

Verifying QUIC implementations using Ivy

Dec 07, 2021
CC
Christophe Crochet

Ambiguities in the IETF QUIC specification (draft-29) hinder precise implementation and complicate compliance verification. Method: This work presents the first comprehensive formal model of draft-29, built within the Ivy framework and integrating state-machine modeling, SMT-based constraint solving, and differential testing to automate compliance validation across seven mainstream QUIC client/server implementations. Contribution/Results: Leveraging formal reverse analysis, we systematically uncover specification ambiguities and propose actionable remediation paths. Our approach identifies multiple critical compliance violations across implementations and pinpoints several interoperability-affecting specification ambiguities—directly informing ongoing IETF standard revisions. The methodology establishes a scalable, end-to-end framework for protocol formal verification, bridging high-level specifications with executable conformance checks while supporting both automated bug detection and specification refinement.

Ensuring QUIC implementations comply with IETF specifications.Extending formal representation from draft-18 to draft-29.Identifying and suggesting corrections for ambiguities in QUIC specification.

Latest Papers

What's happening recently
View more

This study addresses the lack of systematic empirical analysis of the “Security Considerations” sections in Internet standards documents (RFCs). It presents the first large-scale mixed-methods investigation, combining quantitative and qualitative approaches with textual and network analysis to systematically examine the content characteristics, citation structures, and thematic evolution of these sections. The findings reveal that over 90% of RFCs explicitly discuss security issues, yet very few impose mandatory requirements. Security discussions are highly protocol-specific and exhibit citation concentration around a small set of core RFCs. By uncovering the protocol-specific nature, sparse citation patterns, and historical development of security discourse in RFCs, this work fills a critical gap in empirical research on security governance within Internet standardization.

IETFInternet standardsprotocol security

This work addresses the absence of a systematic security framework in existing AI agent protocols—such as MCP and A2A—which undermines secure interactions across trust boundaries. We propose a six-layer protocol stack model tailored for AI agent communication and an implementation-agnostic Agent-Centric Security Model (AASM). To enforce and validate this model, we develop AgentConform, a two-stage conformance checking tool that integrates TLA+ formal modeling, a typed Protocol Intermediate Representation (IR), model checking, and runtime replay verification. For the first time, we formally define eleven security principles and introduce a mechanism for composition safety. Applying our approach to mainstream protocols reveals systemic flaws concerning credential lifecycle management, authorization enforcement, audit integrity, and compositional security; several identified vulnerabilities are already undergoing coordinated disclosure.

agent protocolscomposition safetyconformance testing

This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.

driverhardware communicationmonitor

Hot Scholars

DT

Dacheng Tao

Nanyang Technological University
artificial intelligencemachine learningcomputer visionimage processing
SR

Suthee Ruangwises

Chulalongkorn University
card-based cryptographypuzzlescomputational complexitymatching under preferences
MS

Muhammad Shafique

Professor, ECE, New York University (AD-UAE, Tandon-USA), Director eBRAIN Lab
Embedded Machine LearningBrain-Inspired ComputingRobust & Energy-Efficient System DesignSmart
RZ

Ruichen Zhang

Nanyang Technological University
Next-generation NetworkingEdge IntelligenceAgentic AIReinforcement learning
IK

Imtiaz Karim

Assistant Professor, Computer Science, The University of Texas at Dallas
Network SecuritySystem Security5GProtocol Security