首页> 外文会议> >DaTA 驴 Data-Transparent Authentication Without Communication Overhead
【24h】

DaTA 驴 Data-Transparent Authentication Without Communication Overhead

机译:无需通信开销的DaTA KEY数据透明身份验证

获取原文
获取外文期刊封面目录资料

摘要

With the development of Internet computing techniques, continuous data streams from remote sites are commonly used in scientific and commercial applications. Correspondingly, there is increasing demand of assuring the integrity and authenticity of received data streams. Existing strategies of assuring data integrity and authenticity mainly use message authentication codes (MAC) generated on data blocks and transfer the MAC to the receiver for authentication through either out of band communication or in band communication. Transferring the MAC via out of band communication inevitably introduces communication overhead and additional complexity to synchronize the out of band communication with the data communication. Transferring the MAC via in band channel can be achieved by either appending the MAC to the original data or embedding the MAC into the original data, which would either incur communication overhead or change the original data. It would be desirable to be able to authenticate the stream data without any communication overhead and changing the original data at the same time. To deal with data packet or block loss, many of existing stream data authentication schemes rely on hash chaining, the current usage of which results in uncertainty in authenticating the subsequent data blocks once the first data packet or block loss is detected. In this paper, we propose a novel application layer authentication strategy called DaTA. This authentication scheme requires no change to the original data and causes no additional communication overhead. In addition, it can continue authenticating the rest of data stream even if some data loss has been detected. Our analysis shows that our authentication scheme is robust against packet loss and network jitter. We have implemented a prototype system to evaluate its performance. Our empirical results show that our proposed scheme is efficient and practical under various network conditions
机译:随着Internet计算技术的发展,来自远程站点的连续数据流通常用于科学和商业应用中。相应地,越来越需要确保接收到的数据流的完整性和真实性。现有的确保数据完整性和真实性的策略主要使用在数据块上生成的消息认证码(MAC),然后通过带外通信或带内通信将MAC传输给接收器以进行认证。通过带外通信传输MAC不可避免地会导致通信开销和额外的复杂性,从而使带外通信与数据通信同步。通过将MAC附加到原始数据或将MAC嵌入到原始数据中,可以通过带内通道传输MAC,这将招致通信开销或更改原始数据。期望能够在没有任何通信开销并且同时改变原始数据的情况下认证流数据。为了处理数据分组或块丢失,许多现有的流数据认证方案依赖于散列链,一旦检测到第一个数据分组或块丢失,其当前用法导致认证后续数据块的不确定性。在本文中,我们提出了一种新颖的应用程序层身份验证策略,称为DaTA。此身份验证方案不需要更改原始数据,也不会引起额外的通信开销。此外,即使已检测到某些数据丢失,它也可以继续对其余数据流进行身份验证。我们的分析表明,我们的身份验证方案对数据包丢失和网络抖动具有鲁棒性。我们已经实现了一个原型系统来评估其性能。我们的经验结果表明,我们提出的方案在各种网络条件下都是有效且实用的

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号