Security Analysis and Improvements on Two Homomorphic Authentication Schemes for Network Coding

Security Analysis and Improvements on Two Homomorphic Authentication Schemes for Network Coding
复制标题

两种网络编码同态认证方案的安全分析与改进

DOI:
10.1109/tifs.2016.2515517
复制
发表时间:
2016-05-01
影响因子:
6.8
通讯作者:
Takagi, Tsuyoshi
Takagi, Tsuyoshi
中科院分区:
计算机科学1区
文献类型:
--
作者:
Cheng, Chi;Lee, Jemin;Takagi, Tsuyoshi

文献摘要

被引文献

相似文献

最近,基于同态签名的认证方案被提出,如同态子空间签名(HSS)和基于密钥预分配的标签编码(KEPTE),以抵抗网络编码中的污染攻击。本文证明了对HSS和KEPTE存在有效的多代污染攻击。特别地,我们证明了利用不同代的分组及其签名,攻击者可以创建无效的分组及其相应的签名,并且在中间节点和目的节点通过HSS和KEPTE的验证。在给出更一般的攻击之后,我们分析了所提出的攻击的原因。然后,我们分别针对HSS和KEPTE提出了改进的密钥分发方案。接下来,我们证明了所提出的密钥分发方案能够抵抗所提出的多代污染攻击。最后,我们分析了所提出的HSS和KEPTE密钥分发方案的计算和通信开销,并通过实现实验,证明了所提出的方案增加了系统可以接受的负担。
Recently, based on the homomorphic signatures, the authentication schemes, such as homomorphic subspace signature (HSS) and key predistribution-based tag encoding (KEPTE), have been proposed to resist against pollution attacks in network coding. In this paper, we show that there exists an efficient multi-generation pollution attack on HSS and KEPTE. In particular, we show that using packets and their signatures of different generations, the adversary can create invalid packets and their corresponding signatures that pass the verification of HSS and KEPTE at intermediate the nodes as well as at the destination nodes. After giving a more generic attack, we analyze the cause of the proposed attack. We then propose the improved key distribution schemes for HSS and KEPTE, respectively. Next, we show that the proposed key distribution schemes can combat against the proposed multi-generation pollution attacks. Finally, we analyze the computation and communication costs of the proposed key distribution schemes for HSS and KEPTE, and by implementing experiments, we demonstrate that the proposed schemes add acceptable burden on the system.