{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:G43NPOTBNG2VPSQ3HRQXNEVRER","short_pith_number":"pith:G43NPOTB","schema_version":"1.0","canonical_sha256":"3736d7ba6169b557ca1b3c617692b12460d848d4dfd300d7bb853934a79bf5bb","source":{"kind":"arxiv","id":"1806.07209","version":1},"attestation_state":"computed","paper":{"title":"Formal verification of the YubiKey and YubiHSM APIs in Maude-NPA","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Antonio Gonz\\'alez-Burgue\\~no, Catherine Meadows, Dami\\'an Aparicio, Jos\\'e Meseguer, Santiago Escobar","submitted_at":"2018-06-19T13:19:48Z","abstract_excerpt":"In this paper, we perform an automated analysis of two devices developed by Yubico: YubiKey, designed to authenticate a user to network-based services, and YubiHSM, Yubicos hardware security module. Both are analyzed using the Maude-NPA cryptographic protocol analyzer. Although previous work has been done applying automated tools to these devices, to the best of our knowledge there has been no completely automated analysis to date. This is not surprising, because both YubiKey and YubiHSM, which make use of cryptographic APIs, involve a number of complex features: (i) discrete time in the form "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1806.07209","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-06-19T13:19:48Z","cross_cats_sorted":[],"title_canon_sha256":"54c1589a8c447f184e820df9098f0f39ae0cd03bcd62165e496020cb98b20654","abstract_canon_sha256":"08bcf81cb3c3421488caa44451f6ece1f5f7853bf3b585a50c297c42a4841244"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:12:51.583194Z","signature_b64":"8ZZmyy2muAfJc+vqt+BlepY0OXKFpQhPcbK4Sz8Tq32Pe4tMTlJnwR7PyDII/V+PXVqaZ2eI5I4j43I9Oe1zAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3736d7ba6169b557ca1b3c617692b12460d848d4dfd300d7bb853934a79bf5bb","last_reissued_at":"2026-05-18T00:12:51.582416Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:12:51.582416Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Formal verification of the YubiKey and YubiHSM APIs in Maude-NPA","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Antonio Gonz\\'alez-Burgue\\~no, Catherine Meadows, Dami\\'an Aparicio, Jos\\'e Meseguer, Santiago Escobar","submitted_at":"2018-06-19T13:19:48Z","abstract_excerpt":"In this paper, we perform an automated analysis of two devices developed by Yubico: YubiKey, designed to authenticate a user to network-based services, and YubiHSM, Yubicos hardware security module. Both are analyzed using the Maude-NPA cryptographic protocol analyzer. Although previous work has been done applying automated tools to these devices, to the best of our knowledge there has been no completely automated analysis to date. This is not surprising, because both YubiKey and YubiHSM, which make use of cryptographic APIs, involve a number of complex features: (i) discrete time in the form "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.07209","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1806.07209","created_at":"2026-05-18T00:12:51.582644+00:00"},{"alias_kind":"arxiv_version","alias_value":"1806.07209v1","created_at":"2026-05-18T00:12:51.582644+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.07209","created_at":"2026-05-18T00:12:51.582644+00:00"},{"alias_kind":"pith_short_12","alias_value":"G43NPOTBNG2V","created_at":"2026-05-18T12:32:25.280505+00:00"},{"alias_kind":"pith_short_16","alias_value":"G43NPOTBNG2VPSQ3","created_at":"2026-05-18T12:32:25.280505+00:00"},{"alias_kind":"pith_short_8","alias_value":"G43NPOTB","created_at":"2026-05-18T12:32:25.280505+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER","json":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER.json","graph_json":"https://pith.science/api/pith-number/G43NPOTBNG2VPSQ3HRQXNEVRER/graph.json","events_json":"https://pith.science/api/pith-number/G43NPOTBNG2VPSQ3HRQXNEVRER/events.json","paper":"https://pith.science/paper/G43NPOTB"},"agent_actions":{"view_html":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER","download_json":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER.json","view_paper":"https://pith.science/paper/G43NPOTB","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1806.07209&json=true","fetch_graph":"https://pith.science/api/pith-number/G43NPOTBNG2VPSQ3HRQXNEVRER/graph.json","fetch_events":"https://pith.science/api/pith-number/G43NPOTBNG2VPSQ3HRQXNEVRER/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER/action/timestamp_anchor","attest_storage":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER/action/storage_attestation","attest_author":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER/action/author_attestation","sign_citation":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER/action/citation_signature","submit_replication":"https://pith.science/pith/G43NPOTBNG2VPSQ3HRQXNEVRER/action/replication_record"}},"created_at":"2026-05-18T00:12:51.582644+00:00","updated_at":"2026-05-18T00:12:51.582644+00:00"}