首页> 外文会议>2011 IEEE Conference on Computer Communications Workshops >SANC: Source authentication using network coding
【24h】

SANC: Source authentication using network coding

机译:SANC:使用网络编码的源身份验证

获取原文

摘要

In this paper, we explore the security merits of network coding and potential trade-offs with the widely accepted throughput benefits, especially in multicast scenarios. In particular, we propose a novel Source Authentication using Network Coding (SANC) scheme that can either complement state-of-the-art application-layer authentication schemes proposed in the literature or be used as a stand-alone scheme in network coding-based networks. Towards this objective, we propose a general framework for embedding the authentication information within the network coding Global Encoding Vector. This is attained using a mapping function that enforces a structure on the Global Encoding Vector to facilitate authentication at the destination. First, we illustrate the proposed concept using a simple mapping function, namely a parity bit within each network coding coefficient. Second, we present a detailed security analysis that reveals the security merits of the proposed scheme, contrasted against two baseline schemes that solely adopt application-layer authentication. Finally, we present simulation results pertaining to the network coding performance. Simulation results show that, for plausible scenarios, SANC achieves the same throughput as regular network coding. Furthermore, the results reveal that, for the same packet header, stronger security can be attained. This is confirmed for small as well as scalable networks encountered in practice.
机译:在本文中,我们探索了网络编码的安全性和潜在的权衡,以及广泛接受的吞吐量优势,尤其是在多播场景中。特别是,我们提出了一种使用网络编码(SANC)方案的新颖的源认证,它可以补充文献中提出的最新应用程序层认证方案,也可以用作基于网络编码的独立方案网络。为了实现这一目标,我们提出了一种用于将身份验证信息嵌入网络编码全局编码向量中的通用框架。这是通过使用映射函数来实现的,该函数在Global Encoding Vector上强制实施一种结构,以便于在目标位置进行身份验证。首先,我们使用简单的映射函数(即每个网络编码系数内的奇偶校验位)来说明所提出的概念。其次,我们提供了详细的安全性分析,揭示了所提出方案的安全性优点,与仅采用应用程序层身份验证的两个基准方案形成对比。最后,我们给出了与网络编码性能有关的仿真结果。仿真结果表明,在合理的情况下,SANC可以实现与常规网络编码相同的吞吐量。此外,结果表明,对于相同的分组报头,可以实现更强的安全性。对于实践中遇到的小型网络和可伸缩网络,这已得到确认。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号