Preventing DoS Attack on Hidden Credentials
Guoming Cai, Yadi Wang, Miao Wang, Haiying Gao · 2007
Using hidden credentials, strangers in open environments can establish trust without actually disclosing credentials and policies. However, traditional negotiation protocols with hidden credentials are not satisfactory in that they can't prevent malicious users from tampering negotiation messages or flooding error messages to the recipient. Both of these efforts add the recipient's computational overhead and can cause denial of service (DoS) attack. In this paper we analyze the weaknesses of a single round protocol using hidden credentials and propose an improved trust negotiation protocol to defense against DoS attack on hidden credentials. The proposed protocol can help the recipient to recognize modified messages and authenticate the sender. We also present detailed security analysis for our protocol, and show that our protocol is secure against tampering and flooding aggression.