• DocumentCode
    1556251
  • Title

    Digital signatures for flows and multicasts

  • Author

    Wong, Chung Kei ; Lam, Simon S.

  • Author_Institution
    Dept. of Comput. Sci., Texas Univ., Austin, TX, USA
  • Volume
    7
  • Issue
    4
  • fYear
    1999
  • fDate
    8/1/1999 12:00:00 AM
  • Firstpage
    502
  • Lastpage
    513
  • Abstract
    We present chaining techniques for signing/verifying multiple packets using a single signing/verification operation. We then present flow signing and verification procedures based upon a tree-chaining technique. Since a single signing/verification operation is amortized over many packets, these procedures improve signing and verification rates by one to two orders of magnitude, compared to the approach of signing/verifying packets individually. Our procedures do not depend upon reliable delivery of packets. They also provide delay-bounded signing, and are thus suitable for delay-sensitive flows and multicast applications. To further improve our procedures, we propose several extensions to the Feige-Fiat-Shamir (1987) digital signature scheme to substantially speed up both the signing and verification operations, as well as to allow “adjustable and incremental” verification. The extended scheme, called eFFS, is compared to four other digital signature schemes (RSA, DSA, ElGamal (1985), and Rabin). We compare their signing and verification times, as well as key and signature sizes. We observe that: (1) eFFS is the fastest in signing (by a large margin over any of the other four schemes) and as fast as RSA in verification (tie for a close second behind Rabin (1979)); (2) eFFS allows a tradeoff between memory and signing/verification time; and (3) eFFS allows adjustable and incremental verification by receivers
  • Keywords
    delays; message authentication; multicast communication; packet switching; telecommunication security; trees (mathematics); DSA; ElGamal digital signature; Feige-Fiat-Shamir digital signature; RSA; Rabin digital signature; adjustable/incremental verification; chaining techniques; data security; delay-bounded signing; delay-sensitive flows; eFFS; flow signing; flow verification; key size; memory; multicast applications; multiple packets; signature size; signing rate; signing/verification time; single signing/verification operation; tree-chaining technique; verification rate; Data security; Delay; Digital signatures; IP networks; Unicast; Web and internet services;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/90.793005
  • Filename
    793005