MM-TCN-CMA: Caching-based Multicast Authentication
- The paper introduces caching-based schemes (CMA and CMMA) that precompute authentication proofs to enable immediate verification in high-speed industrial control systems.
- Huffman Hash Trees are used to prioritize likely messages, reducing verification workload and meeting 1–2 ms latency constraints.
- Symmetric cryptography replaces costly public-key operations, ensuring secure multicast authentication in IEC 61850-based substation automation.
Searching arXiv for the specified paper and closely related context. arxiv_search.query({"search_query":"id:(Tefek et al., 2023) OR ti:\"Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems\"","start":0,"max_results":5}) arxiv_search.query({"search_query":"ti:\"Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems\"","start":0,"max_results":10}) The designation MM-TCN-CMA does not appear in the paper that defines the relevant mechanisms. The corresponding technical subject is the pair of schemes Caching-based Message Authentication (CMA) and Caching-based Multicast Message Authentication (CMMA), introduced for immediate authentication of time-critical messages in industrial control systems (ICS), especially IEC 61850-based substation automation in smart grids. Their central idea is to precompute and cache authentication evidence for a set of likely future messages, so that after a message is issued the publisher performs no hashing, and after reception the subscribers avoid expensive public-key verification. The schemes are designed for communication models including unicast, multicast, and broadcast under message rates up to 4,000 messages per second and end-to-end latency budgets of 1–2 ms (Tefek et al., 2023).
1. Problem setting and operational constraints
The paper targets ICS deployments in which authentication failures enable malicious data injection or command injection by illegitimate or compromised devices. The motivating environment is the substation automation system in smart grids using IEC 61850 protocols, with particular attention to GOOSE and SV traffic. GOOSE is described as event-driven, link-layer multicast, whereas SV is periodic, high-rate traffic that can reach 4,000 msg/s. Within this setting, certain protection and control commands must satisfy end-to-end deadlines of 1–2 ms under IEEE 1646 (Tefek et al., 2023).
These constraints exclude straightforward deployment of standard public-key broadcast authentication. The reported evaluation gives ECDSA verification ≈ 2500 µs on BeagleBoard-X15, which is far above the budgets that govern the most time-critical paths. The paper also treats plain TESLA/delayed key disclosure as insufficient for the strictest loops: even a minimal one-interval delay at 4k msg/s adds ≈250 µs, and that delay is itself part of the critical path. This combination of high-rate traffic, multicast dissemination, and immediate-verification requirements motivates a design based exclusively on symmetric primitives and offline precomputation rather than post hoc signing or delayed authentication disclosure (Tefek et al., 2023).
A further enabling condition is the partial predictability of ICS traffic. The paper states that IEC 61850 GOOSE PDUs contain many structured and predictable or slowly varying fields, including IDs, confRev, ndsCom, test, datSet, goID, stNum/sqNum increments, while allData often consists of binary status flags or bounded measurements such as frequency around 50 Hz. This limited entropy is what makes it possible to enumerate likely future messages and precompute authenticators for them.
2. Threat model, trust assumptions, and design objectives
The adversary model assumes remote attackers with network foothold, for example via a compromised VPN or malware, who can inject or forge packets, attempt replays, and observe traffic. The same model excludes local reconfiguration of ICS devices and assumes that BITW devices are non-addressable by remote attackers. The schemes therefore focus on protecting message integrity, source legitimacy, and replay resistance in a constrained but realistic network threat model (Tefek et al., 2023).
The trust model differs between the two schemes. CMA uses pairwise symmetric keys between the source and each destination. CMMA replaces per-destination MAC authentication with a TESLA-style one-way key chain to obtain source–destination asymmetry without computing a separate MAC for each receiver. CMMA therefore requires loose time synchronization and a key disclosure delay satisfying the condition that it is at least the network delay + clock skew. Replay protection additionally relies on application and protocol metadata, including timestamps, sequence numbers, and timeAllowedtoLive.
The design objectives are explicit. The paper aims to achieve immediate verification with symmetric primitives, and to eliminate expensive cryptography both after message issuance and upon reception by pushing work into a precomputation-and-caching stage. This suggests that the schemes are not merely lightweight MAC wrappers; they are organized around temporal decoupling of authentication work from message transmission time, with preauthenticated metadata serving as a stand-in for later cryptographic effort.
3. Core construction: cached authentication via hash trees
The core mechanism is to precompute authentication “evidence” over a candidate set of future messages by building an authenticated binary hash tree. Each candidate message is assigned to a leaf, and only the root is directly authenticated. The tree nodes are retained as private metadata at the source. When the actual message is later known, the publisher transmits the message together with a short proof consisting of the sibling path and the leaf nonce, allowing the receiver to recompute the root and compare it to the root authenticated earlier (Tefek et al., 2023).
Two tree variants are used. A Merkle Hash Tree (MHT) is used when candidates are equally likely. A Huffman Hash Tree (HHT) is constructed from urgency or likelihood weights , so that more likely or more time-critical messages are placed closer to the root. Leaves take the form with a fresh 256-bit nonce per leaf, and internal nodes are . The root for interval is denoted .
The procedures given in the paper define the two protocols precisely.
For CMA, the protocol is:
- Initialize() : establish pairwise keys ; repeat every messages.
- Prioritize(preferences, system_data) : compute the candidate set 0 and normalized weights 1, with 2.
- TreeConstruction(3) 4: build an HHT or MHT, compute 5, and for each destination 6 compute
7
The source shares 8 with destination 9 before the actual message is known.
- Prove(0) 1: collect the proof path and leaf nonce; no hashing is required.
- Pre-Verify(2) 3: the destination verifies 4 and stores 5 for the interval indicated by timeAllowedtoLive.
- Verify(6) 7: the destination recomputes the path to the root and accepts if it matches the stored root.
For CMMA, pairwise MACs are replaced by a TESLA-style authenticated key chain:
- Initialize(8) 9: generate the chain 0, 1, with random 2, and derive MAC keys 3.
- Prioritize(preferences, system_data): as above.
- TreeConstruction(4) 5: compute the root and authenticate it with
6
- Prove(7) 8: send the message and proof immediately, while disclosing 9 only in a later interval 0.
- Verify(1) 2: validate the key chain, recompute the root from the proof, and verify 3.
The architectural difference between the two schemes is summarized below.
| Scheme | Root authentication | Receiver scope |
|---|---|---|
| CMA | 4 | Per destination |
| CMMA | 5 | Shared by all receivers |
| Common mechanism | HHT/MHT proof over cached candidates | Immediate proof-based verification |
This organization allows zero hashes after message issuance at the source. The destination still hashes along the proof path, but avoids public-key verification entirely.
4. Urgency profiles, expected verification cost, and communication overhead
A distinctive feature of the construction is its use of an urgency profile or likelihood profile. For interval 6, the candidate set is 7, and the weights are 8 with 9. The HHT uses these weights so that likely or urgent messages appear closer to the root and therefore require shorter proofs (Tefek et al., 2023).
The paper expresses the resulting verification work in secure-hash equivalents. For CMA with HHT, the total per-message verification cost is approximately 0, where 1 is the depth of leaf 2. For CMMA with HHT, TESLA-related processing adds two further hashes, yielding approximately 3. The expected costs are: 4 for CMA, and
5
for CMMA. By the use of Huffman construction, the expected depth 6 is minimized for the given distribution.
Communication overhead is likewise expressed in hash values per message, with 32 bytes per hash under SHA-256. For CMA with MHT, the proof contributes 7 hash values and the authenticated root contributes one further hash-equivalent, giving 8 hash values in total across 9 destinations. For CMA with HHT, the per-destination total becomes 0. For CMMA, which does not replicate root authentication per subscriber, the totals are 1 hash values for MHT and 2 for HHT, both shared across all receivers.
The paper’s analysis of likelihood distributions reports that four distributions were evaluated, including one with 3 and the remaining mass distributed uniformly. Under such skew, CMMA with HHT significantly outperforms MHT, with the paper linking this to IEC 61850 traffic patterns in which “no state change” messages dominate. A plausible implication is that the benefit of the scheme is maximized precisely in those operational regimes where nominal steady-state traffic vastly outweighs exceptional-state traffic.
5. Security properties, complexity, and state requirements
The schemes use SHA-256 as the hash function, HMAC-SHA-256 as the MAC, and a PRF 4 derived from SHA-256 for TESLA key derivation. Each leaf includes a fresh 256-bit nonce. The optional public-key baseline used for comparison is ECDSA P-256, with a 128-bit security target (Tefek et al., 2023).
Replay protection and freshness are tied to both protocol fields and cache lifetime. The authenticated root is bound to 5, destinations retain root state only for timeAllowedtoLive, GOOSE sequence information through sqNum/stNum aids replay detection, and proofs are indexed by interval and timestamp. The security sketch given in the paper reduces forgery resistance to standard assumptions: in CMA, an adversary that forges a valid proof for a new message under the same root must either recover nonces, violating preimage resistance, or find a collision on the path from leaf to root, violating collision resistance; in CMMA, security additionally depends on the one-wayness of the TESLA key chain and MAC unforgeability. With 256-bit nonces and SHA-256, the forging probability is stated to be negligible, specifically 6 at the targeted security level.
The complexity formulas make the asymmetry between source and destination explicit. Using 7 for the number of subscribers, 8 for the number of unpredictable binary fields, 9 for message arrival rate, 0, and 1 for the realized leaf depth, the source-side secure-hash rates are: 2 for CMA, and
3
for CMMA. Destination-side rates are: 4 for CMA with MHT,
5
for CMA with HHT,
6
for CMMA with MHT, and
7
for CMMA with HHT.
Memory use is dominated by the cached tree. The source stores 8 hashes and 9 nonces. Under SHA-256, each occupies 32 bytes, yielding
0
CMA also stores per-destination MAC state of 1 bytes per interval, whereas CMMA stores a single 32-byte MAC 2. Destinations store the root and root authenticator until expiry, and CMMA receivers additionally maintain the latest TESLA keys and disclosure schedule. This suggests that CMMA is primarily a scaling improvement in receiver multiplicity rather than a change to proof structure itself.
6. Empirical evaluation, robustness, and relation to alternatives
The evaluation uses a BeagleBoard-X15 with a single active core, with trees resident in RAM, and reports averages over 500 runs. With 32 prioritized messages, CMA and CMMA precompute trees in ≈ 210–250 µs. The paper states that CMMA precomputation is ~23 µs faster than tree’d ECDSA across subscriber/message counts because it uses only symmetric hashing, while ECDSA incurs substantial signing and verification costs. The reported precomputation rate is sufficient to support IEC 61850 SV throughput (4000 msg/s) when the true message lies in the prioritized set (Tefek et al., 2023).
At verification time, the baseline HMAC per-message verification costs ≈ 4 µs. For HHT-based CMA and CMMA, best-case latency occurs when the most likely message is placed at depth 1. In that case, CMA ≈ 2 hashes → ~4 µs, and CMMA requires ~6 hashes → ~12 µs because of the added TESLA check, key derivation, and HMAC verification. The paper states that MHT performs worse on average than HHT because MHT ignores likelihood. By contrast, ECDSA verification ≈ 2500 µs, which the paper treats as impractical for ≤2 ms deadlines. The resulting verification latencies, in microseconds rather than milliseconds, leave substantial headroom for transport and application processing.
The paper also addresses robustness and operational edge cases. If the actual message is absent from the current prioritized set, the system can fall back to computing a standard MAC on the fly in the unicast case, or defer to the next interval’s prioritized set in the multicast case, incurring delay comparable to a non-precomputed baseline. In CMMA, if 3 is lost, a receiver can validate 4 by repeated hashing until it matches a previously stored key, providing resilience to packet loss. Out-of-order proofs are handled by indexing them with interval 5 and 6, and expired proofs are rejected after timeAllowedtoLive. The paper further notes that BITW deployment is compatible with legacy devices and requires no application payload changes other than appending proof and root MAC.
Relative to alternative schemes, the paper contrasts CMA and CMMA with RSA/ECDSA, TESLA/delayed key disclosure, polynomial authentication codes, OTS/WOTS variants, and signature amortization. Public-key signatures provide non-repudiation but exceed the required timing envelope. Plain TESLA is efficient but imposes disclosure delay on the message-authentication path. Polynomial and one-time-signature approaches are described as having large keys, large signatures, or state-management burdens, while signature amortization still depends on expensive public-key operations and may be sensitive to loss, jitter, or immediate-verification requirements. The paper’s counterposition is that CMA and CMMA exploit the low entropy and predictability of ICS messages to collapse many potential authenticators into a single authenticated root per interval, with CMMA specifically eliminating per-destination MAC computation for multicast and broadcast. A common misconception is that TESLA alone already solves broadcast authentication for these environments; the reported ≈250 µs disclosure delay at 4k msg/s is presented as evidence that delayed disclosure is still too costly for the tightest protection loops, whereas CMMA shifts authentication of the prioritization outcome ahead of message transmission.
In deployment terms, the paper recommends identifying predictable fields in GOOSE/SV allData and header, building candidate sets per timeAllowedtoLive, choosing HHT when message distributions are skewed, using 256-bit nonces and 256-bit HMAC-SHA-256, setting TESLA chain length 7 to cover the disclosure schedule, and ensuring 8 max network delay + clock skew. CMA is described as suitable for unicast or small multicast groups where pairwise MACs are acceptable, while CMMA is the scalable variant for multicast/broadcast groups with time synchronization.