# Protocol-independent secrecy

@article{Millen2000ProtocolindependentS, title={Protocol-independent secrecy}, author={J. Millen and H. Ruess}, journal={Proceeding 2000 IEEE Symposium on Security and Privacy. S\&P 2000}, year={2000}, pages={110-119} }

Inductive proofs of secrecy invariants for cryptographic protocols can be facilitated by separating the protocol dependent part from the protocol-independent part. Our secrecy theorem encapsulates the use of induction so that the discharge of protocol-specific proof obligations is reduced to first-order reasoning. Also, the verification conditions are modularly associated with the protocol messages. Secrecy proofs for Otway-Rees (1987) and the corrected Needham-Schroeder protocol are given.

