3 ms·
Yes, the network works back from the signed key, which is published last. The TESLA scheme uses a one-way pseudo-random hash function to generate keys, see this
by vii 6y ago
Yes, the network works back from the signed key, which is published last. The TESLA scheme uses a one-way pseudo-random hash function to generate keys, see this paper https://www.esat.kuleuven.be/cosic/publications/article-2749.pdf https://www.esat.kuleuven.be/cosic/publications/article-2749... so if you know the signed key you can generate the others.
That means you can't easily fork a new chain with a K_6' as the receiver can easily check f(K_6') = K_5 where f is a hash function that is hard to reverse.
Once the key has been published, an adversary can use it to generate messages. A requirement in TESLA is that there is close time-synchronisation between the sender and receiver. This is enforced by the safe-packet test as defined in https://tools.ietf.org/html/rfc4082 https://tools.ietf.org/html/rfc4082 which checks that the message packet was received within the time window expected from key signing.
As the satellite positioning systems depend heavily on highly synchronised clocks this is pretty reasonable.
- espadrine 6y agoYou might notice that one of the author of this document is casually the creator of the most widely used cipher in the world.
- RcouF1uZ4gsC 6y agoThat would be Vincent Rijmen of AES and SHA-3 fame.