ACM Home Page
Please provide us with feedback. Feedback
The BiBa one-time signature and broadcast authentication protocol
Full text PdfPdf (269 KB)
Source Conference on Computer and Communications Security archive
Proceedings of the 8th ACM conference on Computer and Communications Security table of contents
Philadelphia, PA, USA
Session: Password Management and Digital Signatures table of contents
Pages: 28 - 37  
Year of Publication: 2001
ISBN:1-58113-385-5
Author
Adrian Perrig  University of California, Berkeley, CA
Sponsor
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 20,   Downloads (12 Months): 84,   Citation Count: 23
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/501983.501988
What is a DOI?

ABSTRACT

We introduce the BiBa signature scheme, a new signature construction that uses one-way functions without trapdoors. BiBa features a low verification overhead and a relatively small signature size. In comparison to other one-way function based signature schemes, BiBa has smaller signatures and is at least twice as fast to verify (which probably makes it one of the fastest signature scheme to date for verification). On the downside, the BiBa public key is large, and the signature generation overhead is higher than previous schemes based on one-way functions without trapdoors (although it can be trivially parallelized).One of the main challenges of securing broadcast communication is source authentication, which allows all receivers to verify the origin of the data. An ideal broadcast authentication protocol should be efficient for the sender and the receiver, have a small communication overhead, allow the receiver to authenticate each individual packet, provide perfect robustness to packet loss, scale to large numbers of receivers, and provide instant authentication (no buffering of data at the sender or receiver side). We are not aware of any previous protocol that satisfies all these properties. We present the BiBa broadcast authentication protocol, a new construction based on the BiBa signature, that achieves all our desired properties, with the tradeoff that it requires a moderate computation overhead for the sender to generate the authentication information, and that it requires loose time synchronization between the sender and receivers.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
 
3
G.Brassard,editor.Advances in Cryptology - CRYPTO '89 ,number 435 in Lecture Notes in Computer Science,Santa Barbara,CA,USA,1990.
 
4
R.Canetti,J.Garay,G.Itkis,D.Micciancio, M.Naor,and B.Pinkas.Multicast security:A taxonomy and some e .cient constructions.In INFOCOMM '99 ,Mar.1999.
 
5
 
6
7
 
8
N.Haller.The S/Key one-time password system.In D.N.G.Chair)andR.S.P.Chair),editors, Symposium on Network and Distributed Systems Security ,San Diego,California,Feb.1994.
 
9
L.Lamport.Discussion with Whit .eld Di .e. http://research.compaq.com/SRC/personal/ lamport/pubs/pubs.html#dig-sig 1975.
 
10
L.Lamport.Constructing digital signatures from a one-way function.Technical Report SRI-CSL-98,SRI International Computer Science Laboratory,Oct. 1979.
11
 
12
R.Merkle.Protocols for public key cryptosystems.In Proceedings of the IEEE Symposium on Research in Security and Privacy ,Oakland,CA,Apr.1980.
 
13
 
14
 
15
Nessie:New European schemes for signatures, integrity,and encryption. http://www.cryptonessie.org 1999.
 
16
A.Perrig,R.Canetti,D.Song,and D.Tygar. E .cient and secure source authentication for ulticast.In Symposium on Network and Distributed Systems Security (NDSS 2001),SanDiego,CA,Feb. 2001.Internet Society.
 
17
 
18
M.O.Rabin.Digitalized signatures.In R.A.DeMillo, D.P.Dobkin,A.K.Jones,and R.J.Lipton,editors, Foundations of Secure Computation ,pages 155 -168. Academic Press,1978.
 
19
Ron Rivest.The MD5 message-digest algorithm. Internet Request for Comment RFC 1321,Internet Engineering Task Force,April 1992.
 
20
Ron Rivest.The RC5 encryption algorithm.In Anderson,editor,Proceedings of the 1st International Workshop on Fast Software Encryption ,volume 809 of Le ture Notes in Computer Science ,pages 86 -96, 1994.Springer-Verlag,Berlin Germany.
 
21
22
23
 
24
R.von Mises.~ber Aufteilungs-und Besetzungswahrscheinlichkeiten.Revue de la Faculte des Sciences de l'Universite d'Istanbul ,4:145 -163, 1939.
 
25
C.K.Wong and S.S.Lam.Digital signatures for flows and ulticasts.In IEEE ICNP '98 ,1998.

CITED BY  23