Abstract
The need for providing assurance In parameter matching in authentication protocols is emphasized by analyzing well-known Needham-Schroeder public-key protocol as well as the public-key extension of widely deployed network authentication protocol Kerberos-5. Authentication protocols achieve their goals when a participant guarantees Its set of parameters to be In accordance with that of the rest of the participants of the protocol. On the other hand, the lack of guarantee suggests possible venues for attacks by a saboteur. The above mentioned protocols exhibit this lack of assurance in parameter matching among participants and hence are succumbed to subtle attacks presented in this paper. We further elaborate the commonalities in the vulnerability of both the protocols.