Security Analysis of DoS Vulnerability in Stream Authentication Schemes Using Hash Chaining
N. KANG · IEICE Transactions on Communications · 2005
SUMMARY In this letter, we show that some stream authenticationschemes using hash chaining are highly vulnerable to denial of service(DoS) attacks. An adversary can disrupt all receivers of group by makinguse of modifying a few packets in those schemes. key words: stream authentication schemes, hash chaining, denial of ser-vice(DoS) attack 1. Introduction Hash chaining provides a cost effective means with a real-time streaming application which needs to support data ori-gin authentication and integrity protection in multicast. Toreduce the cost of digital signature including both the com-putation and the communication overhead in some streamauthentication schemes [1]–[4], the source generates anamortizing signature over a set of packets called a block.As a result, a signature can be generated and transmittedonce a block at the beginning or at the end of a block, whichcontains the hash value of the first or the last packet in ablock. In addition, each packet, which contains only a fewhash values of its previous or succeed packets as an authen-tication tag, is transmitted continuously, thus this is calledhash chaining.From the viewpoint of efficiency, previous work usinghash chaining may be appropriate but can be suffered fromthe denial of service attack. In particular, the DoS attackon the receiver side is much serious problem in multicastthan those in the case of unicast since a single adversary candisrupt thousands of receivers at a time. In this letter, weshow that just one or a few packet’s modifications can causethe failed verification of all packets in the block.1.1 NotationsWe use the following notations throughout this letter: