• Benjamin ToblerEmail author
  • Andrew C. M. Hutchison
Part of the IFIP On-Line Library in Computer Science book series (IFIPAICT, volume 177)


We describe the Spi2Java code generation tool, which we have developed in an attempt to bridge the gap between formal security protocol specification and executable implementation. Implemented in Prolog, Spi2Java can input a formal security protocol specification in a variation of the Spi Calculus, and generate a Java code implementation of that protocol. We give a brief overview of the role of code generation in the wider context of security protocol development. We cover the design and implementation of Spi2Java which we relate to the high integrity code generation requirements identified by Whalen and Heimdahl. By defining a Security Protocol Implementation API that abstracts cryptographic and network communication functionality we show that protocol logic code can be separated from underlying cryptographic algorithm and network stack implementation concerns. The design of this API is discussed, particularly its support for pluggable implementation providers. Spi2Java's functionality is demonstrated by way of example: we specify the Needham-Schroeder Public Key Authentication Protocol, and Lowe's attack on it, in the Spi Calculus and examine a successful attack run using Spi2Java generated implementation of the protocol roles.


Code generation Formal methods Java Process algebra Prolog Security Spi Calculus 

Copyright information

© International Federation for Information Processing 2005

Authors and Affiliations

  1. 1.Department of Computer ScienceUniversity of Cape TownRondeboshSouth Africa

Personalised recommendations