An Efficient Signature-Based Scheme for Securing Network Coding Against Pollution Attacks

An Efficient Signature-Based Scheme for Securing Network Coding Against Pollution Attacks
复制标题

DOI:
10.1109/infocom.2008.199
复制
发表时间:
2008-04
期刊:
IEEE INFOCOM 2008 - The 27th Conference on Computer Communications
影响因子:
--
通讯作者:
Zhen Yu;Yawen Wei;B. Ramkumar;Y. Guan
Zhen Yu;Yawen Wei;B. Ramkumar;Y. Guan
中科院分区:
其他
文献类型:
--
作者:
Zhen Yu;Yawen Wei;B. Ramkumar;Y. Guan

文献摘要

被引文献

相似文献

网络编码提供了网络吞吐量最大化的可能性,在传统的计算机网络、无线传感器网络和点对点系统中得到了各种应用。然而,建立在网络编码之上的应用程序很容易受到污染攻击,在这种攻击中,受损的转发器可以将污染或伪造的消息注入网络。现有的解决污染攻击的方案要么需要一个额外的安全通道,要么会产生很高的计算开销。本文针对采用线性网络编码技术的应用,提出了一种有效的基于签名的污染攻击检测和过滤方案。我们的方案利用了一种新颖的同态签名功能,使源可以将其签名权限委托给转发器,即转发器可以在不与源联系的情况下为其输出消息生成签名。这个不错的属性允许转发器验证接收到的消息,但禁止它们为受污染或伪造的消息创建有效签名。我们的方案不需要任何额外的安全通道,并且可以提供源认证和批量验证。实验结果表明,与现有算法相比,该算法的计算效率提高了10倍以上。此外,我们提出了一种基于更简单的线性签名函数的替代轻量级方案。这种替代方案在计算效率和安全性之间进行了权衡。
Network coding provides the possibility to maximize network throughput and receives various applications in traditional computer networks, wireless sensor networks and peer-to-peer systems. However, the applications built on top of network coding are vulnerable to pollution attacks, in which the compromised forwarders can inject polluted or forged messages into networks. Existing schemes addressing pollution attacks either require an extra secure channel or incur high computation overhead. In this paper, we propose an efficient signature-based scheme to detect and filter pollution attacks for the applications adopting linear network coding techniques. Our scheme exploits a novel homomorphic signature function to enable the source to delegate its signing authority to forwarders, that is, the forwarders can generate the signatures for their output messages without contacting the source. This nice property allows the forwarders to verify the received messages, but prohibit them from creating the valid signatures for polluted or forged ones. Our scheme does not need any extra secure channels, and can provide source authentication and batch verification. Experimental results show that it can improve computation efficiency up to ten times compared to some existing one. In addition, we present an alternate lightweight scheme based on a much simpler linear signature function. This alternate scheme provides a tradeoff between computation efficiency and security.