- Research Article
13
- 10.1016/j.cose.2004.06.010
A hybrid scheme for multicast authentication over lossy networks
- Aug 21, 2004
- Computers & Security
- Heba K Aslan
A hybrid scheme for multicast authentication over lossy networks
With the development of Internet computing techniques, continuous data streams from remote sites are commonly used in scientific and commercial applications. Correspondingly, there is increasing demand of assuring the integrity and authenticity of received data streams. Existing strategies of assuring data integrity and authenticity mainly use message authentication codes (MAC) generated on data blocks and transfer the MAC to the receiver for authentication through either out of band communication or in band communication. Transferring the MAC via out of band communication inevitably introduces communication overhead and additional complexity to synchronize the out of band communication with the data communication. Transferring the MAC via in band channel can be achieved by either appending the MAC to the original data or embedding the MAC into the original data, which would either incur communication overhead or change the original data. It would be desirable to be able to authenticate the stream data without any communication overhead and changing the original data at the same time. To deal with data packet or block loss, many of existing stream data authentication schemes rely on hash chaining, the current usage of which results in uncertainty in authenticating the subsequent data blocks once the first data packet or block loss is detected. In this paper, we propose a novel application layer authentication strategy called DaTA. This authentication scheme requires no change to the original data and causes no additional communication overhead. In addition, it can continue authenticating the rest of data stream even if some data loss has been detected. Our analysis shows that our authentication scheme is robust against packet loss and network jitter. We have implemented a prototype system to evaluate its performance. Our empirical results show that our proposed scheme is efficient and practical under various network conditions
A hybrid scheme for multicast authentication over lossy networks
A hybrid scheme for multicast authentication over lossy networks
Stabilization of Networked Control Systems with Double-sided Packet Losses and Quantizations
Although there has been a lot of work about the synthesis and analysis of networked control systems (NCSs) with quantizers as well as NCSs with packet losses, most results are developed for the case of considering the quantizers and packet losses separately (either only concentrating on the data quantization or only focussing on the packet losses). In this paper, we address the synthesis approach of model predictive control (MPC) for NCSs subject to both data quantization and packet losses. This is motivated by the fact that it is common and natural in NCSs that the issues of the quantization and packet losses are coexisting. We firstly propose a novel model to describe the state and input quantization and the packet losses of the NCS in a unified framework. Further, from the new model, a MPC strategy is developed, which can guarantee the recursive feasibility. Finally, a numerical example is given to illustrate the effectiveness of the proposed method.
Read moreA Hybrid Approach for Authenticating MPEG-2 Streaming Data
There are two main approaches for authenticating digital streams, namely the tree chaining [1] and the hash chaining [2,3]. Both approaches have their disadvantages. Hash chaining is superior for low communication overhead, however, it is not resilient to packet loss and it has a longer verification delay. On the other hand, tree chaining is more robust even if packet loss occurs and with shorter verification delay, but the communication overhead is too high to be tolerable, especially in online applications. In this paper, we try to combine the two techniques and propose a hybrid scheme for authenticating MPEG-2 streaming data, which are still used by real application systems, by taking advantage of the characteristics of MPEG frames. The hybrid approach is shown to be more effective as compared to the other two approaches.
Read moreDP-FEC: Dynamic Probing FEC for High-Performance Real-Time Interactive Video Streaming
High-quality and high-performance real-time interactive video streaming requires both keeping the highest data transmission rate and minimizing data packet loss to achieve the best possible streaming quality. TCP-friendly rate control (TFRC) is the most widely recognized mechanism for achieving relatively smooth data transmission while competing fairly with TCP flows. However, because its data transmission rate depends largely on packet loss conditions, high-quality real-time streaming suffers from a significant degradation of streaming quality due to both a reduction in the data transmission rate and data packet losses. This paper proposes the dynamic probing forward error correction (DP-FEC) mechanism that is effective for high-quality real-time streaming to maximize the streaming quality in a situation in which competing TCP flows pose packet losses to the streaming flow. DP-FEC estimates the network condition by dynamically adjusting the degree of FEC redundancy while trying to recover lost data packets. It effectively utilizes network resources and adjusts the degree of FEC redundancy to improve the playback quality at the user side while minimizing the performance impact of competing TCP flows. We describe the DP-FEC algorithm and evaluate its effectiveness using an NS-2 simulator. The results show that by effectively utilizing network resources, DP-FEC enables to retain higher streaming quality while minimizing the adverse condition on TCP performance, thus achieving TCP friendliness.
Read moreInterest ACK: A Fast Packet Loss Detection Mechanism for Content-Centric Networking
Recently, Content-Centric Networking (CCN) has been extensively studied by networking researchers as one of the promising network architectures for realizing information-centric networks. CCN adopts a fundamentally different communication paradigm from that of the conventional Internet Protocol (IP). Therefore, advanced transport protocols developed for IP cannot be directly used in CCN. In this paper, we propose a packet loss detection mechanism called Interest ACKnowledgement (ACK). Interest ACKs provides information on the history of successful Interest packet receptions at a repository (i.e., content provider), this information is conveyed to the corresponding entity (i.e., content consumer) via the header of Data packets. Interest ACKs enable the entity to quickly and accurately detect Interest and Data packet losses in the network. We conduct simulations to investigate the effectiveness of Interest ACKs in a rather simple network topology. Our results show that Interest ACKs are effective for improving the adaptability, stability, and fairness of CCN with window-based flow control and that packet losses at the repository can be reduced by 10%–20%.
Read moreTCP WELCOME TCP variant for Wireless Environment, Link losses, and COngestion packet loss ModEls
The problem of TCP and all its existing variations within MANETs resides in its inability to distinguish between different data packet loss causes. Thus, TCP has not always the optimum behaviour in front of packet losses which might cause network performance degradation and resources waste. Multiple loss differentiation algorithms (LDAs) have been designed to improve TCP performances. They had been optimized for data networks where only the last link is a wireless link. In these LDAs the most common packet losses that are handled are those due to wireless channel errors or congestion. We show in this paper that a third common packet loss cause, link failure, has to be handled in multi-hop wireless networks such as mobile ad hoc networks (MANETs). In order to handle these three packet loss causes, we propose TCP-WELCOME. This latter follows a two-step process: (i) first, distinguish between most common packet loss causes, and (ii) then, triggers the most appropriate packet loss recovery according to the identified loss cause. The performance evaluation shows that TCP-WELCOME optimizes both energy consumption and throughput. Also, TCP-WELCOME does not change the standard as its loss differentiation and recovery algorithms can operate with the already existing TCP variants.
Read moreComparative Experiments of V2X Security Protocol Based on Hash Chain Cryptography
Vehicle-to-everything (V2X) is the communication technology designed to support road safety for drivers and autonomous driving. The light-weight security solution is crucial to meet the real-time needs of on-board V2X applications. However, most of the recently proposed V2X security protocols—based on the Elliptic Curve Digital Signature Algorithm (ECDSA)—are not efficient enough to support fast processing and reduce the communication overhead between vehicles. ECDSA provides a high-security level at the cost of excessive communication and computation overhead, which motivates us to propose a light-weight message authentication and privacy preservation protocol for V2X communications. The proposed protocol achieves highly secure message authentication at a substantially lower cost by introducing a hash chain of secret keys for a Message Authentication Code (MAC). We implemented the proposed protocol using commercial V2X devices to prove its performance advantages over the standard and non-standard protocols. We constructed real V2X networks using commercial V2X devices that run our implemented protocol. Our extensive experiments with real networks demonstrate that the proposed protocol reduces the communication overhead by 6 times and computation overhead by more than 100 times compared with the IEEE1609.2 standard. Moreover, the proposed protocol reduces the communication overhead by 4 times and the computation overhead by up to 100 times compared with a non-standard security protocol, TESLA. The proposed protocol substantially reduces the average end-to-end delay to 2.5 ms, which is a 24- and 28-fold reduction, respectively, compared with the IEEE1609 and TESLA protocols.
Read moreDensity Peaks Clustering Algorithm for Large-scale Data Based on Divide-and-Conquer Strategy
Density peaks clustering algorithm is a simple but effective clustering method, which requires fewer parameters and iteration, and can determine the number of clusters. But this algorithm has high complexity of time and space which makes it is unsuitable to cluster large-scale data. So that this paper proposes a density peaks clustering algorithm based on the divide-and-conquer strategy. Firstly, divides the large-scale data into a series of data blocks consistent with the original data distribution, then performs density peaks clustering on a randomly selected block to get the clustering center of the data block. Since the data block has the same distribution with the original large-scale data, the clustering center can be used as the clustering center of the original data. Finally, allocates the remaining data blocks to the corresponding clustering center to obtain the final clustering result. Experimental results on real and synthetic datasets verify the effectiveness of the proposed algorithm.
Read moreFPGA Implementation of Viterbi Algorithm for Decoding of Convolution Codes
Convolutional code is a coding scheme used in communication systems including deep space communications and wireless communications.It provides an alternative approach to block codes for transmission over a noisy channel.The block codes can be applied only for the block of data.The Convolutional coding has an advantage over the block codes in that it can be applied to a continuous data stream as well as to blocks of data.Viterbi decoder employed in digital wireless communication plays a rife role in the overall power consumption of trellis coded modulation decoder.Power reduction in Viterbi decoder could be achieved by reducing the number of states.A pre-computation architecture with T-algorithm was implemented for this purpose, and when we compare this result with full Trellis Viterbi decoder, this approach significantly reduces power consumption without degrading decoding speed.Convolutional encoding with viterbi decoding is a powerful FEC technique that is particularly suited to a channel in which the transmitted signal is corrupted mainly by Additive White Gaussian Noise (AWGN).It operates on data stream and has memory that uses previous bits to encode.The Viterbi Algorithm (VA) is proposed, used for decoding a bit stream that has been encoded using FEC code.The Convolutional encoder adds redundancy to a continuous stream of input data by using a linear shift register.A pre-computation architecture with Viterbi algorithm is implemented for this purpose, Viterbi (Convolutional) encoder and Viterbi decoder are designed and implemented using FPGA technology, which are the essential blocks in digital communication systems.It is particularly suited to a channel in which the transmitted signal is corrupted mainly by AWGN.The Viterbi decoder of Constraint length 7 and code rate ½ is considered.The design is implemented using verilog on Xilinx Spartan 3E and advanced Spartan 6 board and the results and Comparisons are presented.
Read moreA cluster-based routing method with authentication capability in Vehicular Ad hoc Networks (VANETs)
A cluster-based routing method with authentication capability in Vehicular Ad hoc Networks (VANETs)
VHDL Design of a Scalable VLSI Sorting Device Based on Pipelined Computation
This paper describes the VHDL design of a sorting algorithm, aiming at defining an elementary sorting unit as a building block of VLSI devices which require a huge number of sorting units. As such, care was taken to reach a reasonable low value of the area-time parameter. A sorting VLSI device, in fact, can be built as a cascade of elementary sorting units which process the input stream in a pipeline fashion: as the processing goes on, a wave of sorted numbers propagates towards the output ports. The paper describes the design starting from an initial theoretical analysis of the algorithm's complexity to a VHDL behavioural analysis of the proposed architecture to a structural synthesis of a sorting block based on the Alliance tools to, finally, a silicon synthesis which was worked out again using Alliance. Two points in the proposed design are particularly noteworthy. First, the sorting architecture is suitable for treating a continuous stream of input data rather than a block of data as in many other designs. Secondly, the proposed design reaches a reasonable compromise between area and time, as it yields an A T product which compares favourably with the theoretical lower bound.
Read moreEnd-to-end secure delivery of scalable video streams
We investigate the problem of securing the delivery of scalable video streams so that receivers can ensure the authenticity (originality and integrity) of the video. Our focus is on recent scalable video coding techniques, e.g., H.264/SVC, that can provide three scalability types at the same time: temporal, spatial, and quality (or PSNR). This three-dimensional scalability offers a great flexibility that enables customizing video streams for a wide range of heterogeneous receivers and network conditions. This flexibility, however, is not supported by current stream authentication schemes in the literature. We propose an efficient authentication scheme that accounts for the full scalability of video streams: it enables verification of all possible substreams that can be extracted and decoded from the original stream. Our evaluation study shows that the proposed authentication scheme is robust against packet losses, adds low communication and computation overheads, and is suitable for live streaming systems as it has short delay.
Read moreA Study of VoIP Performance in Anonymous Network - The Onion Routing (Tor)
Information technology is developing rapidly, especially in the field of computer science, telecommunications and information systems. In the early days of telecommunications, voice networks could not be combined with data networks. However, more recently it became possible to integrate data, audio and video services onto a single network, known as a multimedia network. The capabilities of the Internet are also rapidly increasing, and now, in addition to data packets (email, web browsing) the Internet transfers audio and video packets. Voice over Internet Protocol (VoIP) is a multimedia service. This technology can be used to transmit audio, video, and data packets. Consequently, it is becoming the most preferred communications technology. VoIP will eventually replace the use of traditional telephony – Public Switched Telephone Networks (PSTN), although the switchover process is challenging. A chief concern it that, while PSTN transmits audio packets over a closed network, VoIP sends audio packets using an open network – the Internet. In PSTN, eavesdroppers must have direct access to physical network to obtain information from communications. Whereas with VoIP, eavesdroppers can monitor data packets from they are connected to the Internet. Hence, security and privacy are important considerations when switching to VoIP systems. One solution is anonymous systems, which can be used to implement security and privacy protocols. However, this typically reduces the Quality of Service (QoS) of the VoIP. This empirical research study examines VoIP performance in an anonymous network – The Onion Routing (Tor). Two scenarios are implemented using the real Tor network to investigate three QoS metrics for VoIP: latency, jitter and packet loss. As recommended, latency in VoIP should be less than 400 ms, jitter should be less than 50 ms and packet loss should not be more than 5%. In addition, the research calculates the probability of attackers in the two scenarios implemented and evaluate Tor network forecasting. Experiments were conducted in reference to two scenarios. The first scenario is VoIP calls routed through a Tor network with three Tor relays (default Tor). And the second scenario is VoIP calls routed through a Tor network with two Tor relays. Experiments were performed in three periods; December 2012, July 2013, and October 2013. During each experimental time period, a hundred calls were captured for each scenario. Experimental results show that the QoS of VoIP over the two Tor relays was better than the VoIP over the three Tor relays. However, a probability of attackers calculation found that the VoIP with three Tor relays returned better anonymity than that with two Tor relays. The best results were returned over the experimental period in July 2013, when the acceptable calls using two Tor relays reached 64 calls at 5% packet loss. Meanwhile, the worst experimental results were returned in October 2013, when acceptable calls numbered 11 using three Tor relays at 1% packet loss. At the end of 2013, the actual data for relay numbers and bandwidth approached forecast result with time series analysis. Meanwhile, the numbers of Tor users differed from the Tor users forecast. In August 2013, Tor users increased dramatically; this is attributed to the fact that BotNet attack was using the Tor network to attack their target leading to a fivefold increase.
Read moreEfficient Method for Continuous IoT Data Stream Indexing in the Fog-Cloud Computing Level
Internet of Things (IoT) systems include many smart devices that continuously generate massive spatio-temporal data, which can be difficult to process. These continuous data streams need to be stored smartly so that query searches are efficient. In this work, we propose an efficient method, in the fog-cloud computing architecture, to index continuous and heterogeneous data streams in metric space. This method divides the fog layer into three levels: clustering, clusters processing and indexing. The Density-Based Spatial Clustering of Applications with Noise (DBSCAN) algorithm is used to group the data from each stream into homogeneous clusters at the clustering fog level. Each cluster in the first data stream is stored in the clusters processing fog level and indexed directly in the indexing fog level in a Binary tree with Hyperplane (BH tree). The indexing of clusters in the subsequent data stream is determined by the coefficient of variation (CV) value of the union of the new cluster with the existing clusters in the cluster processing fog layer. An analysis and comparison of our experimental results with other results in the literature demonstrated the effectiveness of the CV method in reducing energy consumption during BH tree construction, as well as reducing the search time and energy consumption during a k Nearest Neighbor (kNN) parallel query search.
Read moreEnhanced Reliable ACK (ERACK) Scheme for Detecting Misbehaving Nodes in MANETs
In Mobile Ad Hoc Networks (MANETs), the process of sending end-to-end acknowledgement (ACK) for each packet by the destination, causes unnecessary overhead. This paper proposes an Enhanced Reliable ACK (ERACK) scheme for detecting misbehaving attacks in MANET. Initially, reliable multiple paths are established by measuring the path reliability. For defending the data transferred from the dispatcher, one-way hash chain based Message Authentication Code (MAC) is utilised. If the packet loss count is above a threshold, then Secure ACK (S-ACK) mode is activated which identifies the misbehaving node. The source then generates a Misbehavior Report Authentication (MRA) message which is transmitted to the destination using the path with next higher reliability. By experimental results it is shown that the ERACK method decreases the packet loss and delay while ensuring the successful delivery of MRA to the destination.
Read more