Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems
Utku Tefek, Ertem Esiner, Daisuke Mashima, Binbin Chen, Yih-Chun Hu

TL;DR
This paper introduces lightweight, caching-based multicast message authentication schemes, CMA and CMMA, designed for high-speed, low-latency industrial control systems to prevent malicious data injection efficiently.
Contribution
The paper presents novel precomputation and caching schemes that eliminate cryptographic overhead during message verification in time-critical ICS environments.
Findings
C(M)MA achieves minimal runtime verification overhead.
The schemes support message rates of thousands per second.
Feasibility demonstrated in smart grid substation automation.
Abstract
Attacks against industrial control systems (ICSs) often exploit the insufficiency of authentication mechanisms. Verifying whether the received messages are intact and issued by legitimate sources can prevent malicious data/command injection by illegitimate or compromised devices. However, the key challenge is to introduce message authentication for various ICS communication models, including multicast or broadcast, with a messaging rate that can be as high as thousands of messages per second, within very stringent latency constraints. For example, certain commands for protection in smart grids must be delivered within 2 milliseconds, ruling out public-key cryptography. This paper proposes two lightweight message authentication schemes, named CMA and its multicast variant CMMA, that perform precomputation and caching to authenticate future messages. With minimal precomputation and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
