应用科学学报 ›› 2006, Vol. 24 ›› Issue (4): 349-353.

• 论文 • 上一篇    下一篇

一种与路由结合的802.16多跳双向认证SA管理机制

王兴建, 胡爱群, 黄玉划   

  1. 东南大学信息安全研究中心, 江苏南京 210096
  • 收稿日期:2005-01-15 修回日期:2005-04-25 出版日期:2006-07-31 发布日期:2006-07-31
  • 作者简介:王兴建,博士生,研究方向:无线网络安全和QoS;E-mail:wxj_wuka@yahoo.com.cn;胡爱群,教授,博导,研究方向:宽带无线网络,E-mail:aqhu@seu.edu.cn
  • 基金资助:
    国家"863"高技术研究发展计划(2003AA143040),江苏省网络与信息安全实验室资助项目(BM2003201)

An IEEE 802.16 Multi-hop Mutual SA Management Mechanism Associated with Hypo-optimal Routing

WANG Xing-jian, HU Ai-qun, HUANG Yu-hua   

  1. Research Center of Information Security, Southeast University, Nanjing 210096, China
  • Received:2005-01-15 Revised:2005-04-25 Online:2006-07-31 Published:2006-07-31

摘要: 先提出了一种更为强健高效的PMP双向SA(安全关联)认证机制,只在首次认证时传递证书,降低了网络传输开销.随后提出了一种和次优路由结合的mesh多跳双向认证SA管理机制.与原有机制相比,这两种机制是前向安全的,对中间节点的攻击具有强安全性,同时,mesh多跳双向认证SA管理机制在按需路由建立前使用次优路由传递管理信息可减少服务流建立时延.

关键词: 节点, mesh, IEEE802.16, 多跳双向认证, 次优路由

Abstract: IEEE 802.16-2004 wireless-MAN standard supports two types of network architecture, i.e., PMP and mesh. In this paper, we first introduce a more robust and efficient PMP mutual authentication SA (security association) mechanism, which removes the certificate transmission after the first authentication to reduce system cost.A multi-hop mutual authentication SA mechanism associated with hypo-optimal routing strategy in mesh is then proposed.These two mechanisms guarantee a degree of protection comparable to those defined in the 802.16 protocol, while provide forward security and immunity against attacks on intermediate nodes.The routing strategy attached to mesh SA mechanism makes it possible to transmit management information before establishment of the on-demand data routing to shorten the service flow creation delay.

Key words: multi-hop mutual authentication, IEEE 802.16, mesh, node, hypo-optimal routing

中图分类号: