DocumentCode :
1556251
Title :
Digital signatures for flows and multicasts
Author :
Wong, Chung Kei ; Lam, Simon S.
Author_Institution :
Dept. of Comput. Sci., Texas Univ., Austin, TX, USA
Volume :
7
Issue :
4
fYear :
1999
fDate :
8/1/1999 12:00:00 AM
Firstpage :
502
Lastpage :
513
Abstract :
We present chaining techniques for signing/verifying multiple packets using a single signing/verification operation. We then present flow signing and verification procedures based upon a tree-chaining technique. Since a single signing/verification operation is amortized over many packets, these procedures improve signing and verification rates by one to two orders of magnitude, compared to the approach of signing/verifying packets individually. Our procedures do not depend upon reliable delivery of packets. They also provide delay-bounded signing, and are thus suitable for delay-sensitive flows and multicast applications. To further improve our procedures, we propose several extensions to the Feige-Fiat-Shamir (1987) digital signature scheme to substantially speed up both the signing and verification operations, as well as to allow “adjustable and incremental” verification. The extended scheme, called eFFS, is compared to four other digital signature schemes (RSA, DSA, ElGamal (1985), and Rabin). We compare their signing and verification times, as well as key and signature sizes. We observe that: (1) eFFS is the fastest in signing (by a large margin over any of the other four schemes) and as fast as RSA in verification (tie for a close second behind Rabin (1979)); (2) eFFS allows a tradeoff between memory and signing/verification time; and (3) eFFS allows adjustable and incremental verification by receivers
Keywords :
delays; message authentication; multicast communication; packet switching; telecommunication security; trees (mathematics); DSA; ElGamal digital signature; Feige-Fiat-Shamir digital signature; RSA; Rabin digital signature; adjustable/incremental verification; chaining techniques; data security; delay-bounded signing; delay-sensitive flows; eFFS; flow signing; flow verification; key size; memory; multicast applications; multiple packets; signature size; signing rate; signing/verification time; single signing/verification operation; tree-chaining technique; verification rate; Data security; Delay; Digital signatures; IP networks; Unicast; Web and internet services;
fLanguage :
English
Journal_Title :
Networking, IEEE/ACM Transactions on
Publisher :
ieee
ISSN :
1063-6692
Type :
jour
DOI :
10.1109/90.793005
Filename :
793005
Link To Document :
بازگشت