DocumentCode
3058452
Title
An Optimized Double Cache Technique for Efficient Use of Forward-secure Signature Schemes
Author
Berbecaru, Diana ; Albertalli, Luca
Author_Institution
Politecnico di Torino, Turin
fYear
2008
fDate
13-15 Feb. 2008
Firstpage
581
Lastpage
589
Abstract
The greatest threat against the security of a digital signature scheme is the exposure of the secret (signing) key, due to the compromise of the security of the underlying system or machine storing the key. This attack is known as key exposure attack, and hypothetically any security service that is provided via an online server digitally signing in real time the data (e.g. timestamping server) is exposed to such an attack. In this paper we perform one step forward towards optimizing the usage of Forward Secure Signature (FSS) schemes on large scale to mitigate key exposure attacks. First of all, we have performed extended tests with the already implemented OpenSSL-based libfss library, which supports several generic FSS schemes, such as ISum, BMTree or MMM schemes. We observed that one critical phase is the key update phase, which typically requires a large amount of time and resources. Thus, we propose an optimization technique for ISum scheme´s implementation (named double cache updating technique), which makes use of two dedicated caches: one for the keys and one for the intermediate (hash) nodes. The results obtained are encouraging since the proposed double cache technique provides a constant key update time and a low memory footprint.
Keywords
cache storage; digital signatures; ISum scheme; OpenSSL-based libfss library; digital signature; double cache updating technique; forward secure signature; forward-secure signature scheme; key exposure attack; optimization technique; optimized double cache; secret signing key; security service; Authentication; Communication system security; Data security; Digital signatures; Frequency selective surfaces; Large-scale systems; Libraries; Performance evaluation; Real time systems; Testing; backward secrecy; double cache technique; generic FSS schemes;
fLanguage
English
Publisher
ieee
Conference_Titel
Parallel, Distributed and Network-Based Processing, 2008. PDP 2008. 16th Euromicro Conference on
Conference_Location
Toulouse
ISSN
1066-6192
Print_ISBN
978-0-7695-3089-5
Type
conf
DOI
10.1109/PDP.2008.64
Filename
4457173
Link To Document