摘要
先提出了一种更为强健高效的PMP双向SA(安全关联)认证机制,只在首次认证时传递证书,降低了网络传输开销.随后提出了一种和次优路由结合的mesh多跳双向认证SA管理机制.与原有机制相比,这两种机制是前向安全的,对中间节点的攻击具有强安全性,同时,mesh多跳双向认证SA管理机制在按需路由建立前使用次优路由传递管理信息可减少服务流建立时延.
IEEE 802.16-2004 wireless-MAN standard supports two types of network architecture, i.e., PMP and mesh. In this paper, we first introduce a more robust and efficient PMP mutual authentication SA (security association) mechanism, which removes the certificate transmission after the first authentication to reduce system cost. A multi-hop mutual authentication SA mechanism associated with hypo-optimal routing strategy in mesh is then proposed. These two mechanisms guarantee a degree of protection comparable to those defined in the 802.16 protocol, while provide forward security and immunity against attacks on intermediate nodes. The routing strategy attached to mesh SA mechanism makes it possible to transmit management information before establishment of the on-demand data routing to shorten the service flow creation delay.
出处
《应用科学学报》
CAS
CSCD
北大核心
2006年第4期349-353,共5页
Journal of Applied Sciences
基金
国家"863"高技术研究发展计划(2003AA143040)
江苏省网络与信息安全实验室资助项目(BM2003201)