首页> 外文期刊>ACM transactions on sensor networks >Containing Bogus Packet Insertion Attacks for Broadcast Authentication in Sensor Networks
【24h】

Containing Bogus Packet Insertion Attacks for Broadcast Authentication in Sensor Networks

机译:包含伪造的数据包插入攻击,用于传感器网络中的广播身份验证

获取原文
获取原文并翻译 | 示例

摘要

Broadcast is a critical communication primitive in wireless sensor networks. The multihop nature of sensor networks makes it necessary for sensor nodes to forward broadcast messages so that the messages can reach an entire network. Authentication of broadcast messages is an important but challenging problem in sensor networks. Public key cryptography (PKC) has been used recently to address this problem. However, PKC-based authentication techniques are susceptible to bogus packet insertion attacks in which attackers keep broadcasting bogus messages and force resource-constrained sensor nodes to forward such messages. Moreover, because it takes time to do signature verifications, it is impractical for each node to authenticate every received message before forwarding it. In this article, we propose a dynamic window scheme to thwart the aforementioned bogus packet insertion attacks which permits sensor nodes to efficiently broadcast messages. Within this scheme, a sensor node has the ability to determine whether or not to verify an incoming message before forwarding the message. We further study the property of this dynamic window scheme and investigate the best strategy for thwarting bogus packet insertion attacks. We propose three strategies for finding the optimal parameters by an improved additive increase multiplicative decrease (AIMD) window updating function so that the proposed dynamic window scheme can achieve the best overall performance with respect to the authentication and forwarding times of messages. Numerical validations show that our proposed scheme performs very well in terms of energy saving and broadcast delays based on three different metrics, including average authentication delays, the percentage of nodes receiving fake messages, and the percentage of nodes forwarding fake messages.
机译:广播是无线传感器网络中的关键通信原语。传感器网络的多跳性质使传感器节点必须转发广播消息,以便消息可以到达整个网络。广播消息的身份验证是传感器网络中一个重要但具有挑战性的问题。公钥密码术(PKC)最近已用于解决此问题。但是,基于PKC的身份验证技术容易受到伪造的分组插入攻击,在这种攻击中,攻击者不断广播伪造的消息,并迫使资源受限的传感器节点转发此类消息。而且,由于花费时间来进行签名验证,因此每个节点在转发每个接收到的消息之前对其进行身份验证是不切实际的。在本文中,我们提出了一种动态窗口方案来阻止上述伪造的数据包插入攻击,该攻击允许传感器节点有效地广播消息。在此方案中,传感器节点具有在转发消息之前确定是否验证传入消息的能力。我们进一步研究了这种动态窗口方案的性质,并研究了阻止伪造数据包插入攻击的最佳策略。我们提出了三种策略,通过改进的加性增加乘性减少(AIMD)窗口更新功能来查找最佳参数,从而使所提出的动态窗口方案在消息的身份验证和转发时间方面可以达到最佳的整体性能。数值验证表明,基于三种不同的指标,我们的方案在节能和广播延迟方面表现出色,包括平均身份验证延迟,接收虚假消息的节点百分比和转发虚假消息的节点百分比。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号