Repository logo
  • English
  • 中文
Log In
Have you forgotten your password?
  1. Home
  2. College of Electrical Engineering and Computer Science / 電機資訊學院
  3. Electrical Engineering / 電機工程學系
  4. Aggregating Symmetric Authentication: From Motes to Clouds
 
  • Details

Aggregating Symmetric Authentication: From Motes to Clouds

Date Issued
2013
Date
2013
Author(s)
Chen, Yu-Shian
URI
http://ntur.lib.ntu.edu.tw//handle/246246/262890
Abstract
This thesis discusses the aggregation of authentication created purely from symmetric cryptography. It also means that the authentication tags are aggregated in a symmetric way, or simply via hash functions. The contents of this work can be can be roughly classified as the applications and theory parts. From the aspect of applications, it consists of four computational applications regarding data and communication authenticity, spreading from micro-scaled sensor networks to macro-scaled cloud. These topics include (1) dynamic authenticated dictionary, (2) broadcast authentication in sensor networks, (3) en-route false injection filtering, and (4) verifiable encrypted cloud storage. Two canonical hash-based data structures are employed, the Merkle Tree (MT) and the Bloom Filter (BF). 1. Dynamic authenticated dictionary: As a generic computation paradigm, the authenticated dictionary is to verify that the delegated remote correctly store the outsourced data. Prior solutions, mostly adopting the Merkle Tree (MT), are either only suitable for static dictionary or lack of efficient structures. We propose several novel approaches to extend the MT''s ability of data update and negative query. Unlike the other hash-based schemes for authenticating dynamic data, these proposals retains the structural simplicity of MT. 2. Broadcast authentication: Broadcast authentication (BA) is a crucial foundation of wireless sensor networks (WSN). Limited by computation and energy resources, the sensor motes should not directly adopt asymmetric cryptography. Hence, the μTESLA protocol has been acting as the major role for doing BA in WSN. The chain structure of TESLA, however, brings inconvenience to update of authentication source. To prolong durability and support self-healing property, the Curtain applies compressed Bloom filters (CBF) to multiple μTESLA. It greatly reduces the network communication overhead at the cost of a moderate memory usage in receiving motes. The mCurtain, an extended version of Curtain, works for scenario of multiple senders. It allows the system to dynamically add and revoke senders. 3. False injection filtering: Lightweight en-route authentication is a challenging task in wireless multi-hop networks. An adversary can inject false data into the system, incurring redundant message forwarding, consuming node resources, and degrading network performance. Although the injection might be identified, en-routers have paid price for them. We utilize Bloom filter techniques, again, to build an authentication manifest called en-route authentication bitmap (EAB). EAB helps nodes on the routing path to filter out false data in high success rate, thus confine the injection attacks within the one or two hops from the adversary. The evaluation shows that EAB effectively protect the forwarding path of tens of hops with only a few bytes cost. 4. Verifiable encrypted cloud storage: A cloud storage service is never sufficient if it only guarantees one of data confidentiality and integrity. Remote storage without encryption could expose private information to outsiders; while storage without integrity could be appended with garbled and useless cipher. This paper presents the Stratus, an integrated encrypted storage atop of heterogeneous cloud storage. Standing on user''s perspective, Stratus focuses on offering transparent and convenient access and integrity verification of the data outsourced. Also, Stratus preserves implicitly the folder hierarchy of the original storage and allows painless data migration and sharing without backward decryption. By the technique of dummy list, Stratus is able to perform lazy deletion, reducing access overhead. Other salient features of Stratus include assured deletion and space query in O(log n). Finally, from the aspect of theory, the work derives a rigorous proof of the security extreme of aggregated authentication. First, we give a precise definition of Aggregate message authentication codes (AMACs) with the property of one-the-fly (OTF) verification. The AMACs encompass portions of each previous mentioned application. Combing information theory, authentication theory, and Bloom computation, the theoretical security extreme of such authentication is derived and proved. The results correspond to prior research adopting other methodologies in literature. The Merkle trees and Bloom filters, both ancient and simple hash-based structures, are the two foundations of this thesis. Readers will find that the old tools might be more efficient in tackling emerging problems, even in the modern computational world dominated by asymmetric cryptography.
Subjects
彙集
認證
Merkle 雜湊樹
Bloom 過濾器
認證字典
感測網路
雲儲存
Type
thesis
File(s)
Loading...
Thumbnail Image
Name

ntu-102-D94921021-1.pdf

Size

23.32 KB

Format

Adobe PDF

Checksum

(MD5):65a56a09b38e2402ba160b1e38c234ec

臺大位居世界頂尖大學之列,為永久珍藏及向國際展現本校豐碩的研究成果及學術能量,圖書館整合機構典藏(NTUR)與學術庫(AH)不同功能平台,成為臺大學術典藏NTU scholars。期能整合研究能量、促進交流合作、保存學術產出、推廣研究成果。

To permanently archive and promote researcher profiles and scholarly works, Library integrates the services of “NTU Repository” with “Academic Hub” to form NTU Scholars.

總館學科館員 (Main Library)
醫學圖書館學科館員 (Medical Library)
社會科學院辜振甫紀念圖書館學科館員 (Social Sciences Library)

開放取用是從使用者角度提升資訊取用性的社會運動,應用在學術研究上是透過將研究著作公開供使用者自由取閱,以促進學術傳播及因應期刊訂購費用逐年攀升。同時可加速研究發展、提升研究影響力,NTU Scholars即為本校的開放取用典藏(OA Archive)平台。(點選深入了解OA)

  • 請確認所上傳的全文是原創的內容,若該文件包含部分內容的版權非匯入者所有,或由第三方贊助與合作完成,請確認該版權所有者及第三方同意提供此授權。
    Please represent that the submission is your original work, and that you have the right to grant the rights to upload.
  • 若欲上傳已出版的全文電子檔,可使用Open policy finder網站查詢,以確認出版單位之版權政策。
    Please use Open policy finder to find a summary of permissions that are normally given as part of each publisher's copyright transfer agreement.
  • 網站簡介 (Quickstart Guide)
  • 使用手冊 (Instruction Manual)
  • 線上預約服務 (Booking Service)
  • 方案一:臺灣大學計算機中心帳號登入
    (With C&INC Email Account)
  • 方案二:ORCID帳號登入 (With ORCID)
  • 方案一:定期更新ORCID者,以ID匯入 (Search for identifier (ORCID))
  • 方案二:自行建檔 (Default mode Submission)
  • 方案三:學科館員協助匯入 (Email worklist to subject librarians)

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science