Secure and Lightweight Subflow Establishment of Multipath-TCP

Gunhee Noh, Hoorin Park, Heejun Roh, Wonjun Lee · IEEE Access · 2019

Multipath Transmission Control Protocol (MPTCP) is an approach towards high-throughput and efficient load balancing over multiple paths. Each of paths forms a TCP connection with an IP address, and those can be implemented as multiple network interfaces or multiple ports within a network interface. In this paper, we focus on the multiple network interfaces environment. Each network interface with an IP address is called as a subflow. A subflow is a TCP connection which can have a different internet path identified by IP addresses of source and destination network interfaces. To control these multiple subflows, MPTCP supports many options. Specifically, to establish a new subflow, MPTCP uses anADD_ADDRoption. A host sendsADD_ADDRoption to inform another host of its IP address, and then, the host receivingADD_ADDRoption tries to establish a subflow at the address ofADD_ADDRoption. However, by forging theADD_ADDRoption, an attacker can create a fake subflow that passes through itself and eventually hijack the connection between both end hosts. In a previous study, Hash-based Message Authentication (HMAC) was added to theADD_ADDRoption, preventing it from being forged. Nevertheless, since the keys for generating HMAC can be leaked during three-way handshake, a variant of theADD_ADDRattack called the persistentADD_ADDRattack can be possible. To this end, we propose a protocol that can prevent theADD_ADDRattacks by backward confirmation of theADD_ADDRoption without encryption. The main idea of our proposal is to apply a digital signature scheme for the backward confirmation. We show security analysis for the proposed protocol and compare with the previous studies in terms of time/space overheads.

Read the paper · More papers on PaperTik