Sun 6 Dec, 2009
Pre-Authentication Filters: Providing DoS Resistance for Signature Based Broadcast Authentication in Sensor Networks
Comments (0) Filed under: NetworkingTags: Broadcast Authentication, Donggang Liu, DoS Attacks, Peng Ning, Qi Dong, Security, Sensor networks
Author:Qi Dong, Donggang Liu,Peng Ning
Description:
Recent studies have demonstrated that it is possible to per form public key cryptographic operations on the resource constrained sensor platforms. However, the significant resource consumption imposed by public key cryptographic operations makes such mechanisms easy targets of Denial of Service (DoS) attacks. For example, if digital signatures such as ECDSA are used directly for broadcast authenti cation without further protection, an attacker can simply broadcast forged packets and force the receiving nodes to perform a large number of unnecessary signature verifications, eventually exhausting their battery power. This paper studies how to deal with such DoS attacks when signatures are used for broadcast authentication in sensor networks.In particular, this paper presents two filtering techniques,a group based filter and a key chain based filter, to handle DoS attacks against signature verification. Both methods can significantly reduce the number of unnecessary signature verifications that a sensor node hasto perform. The analytical results also show t