首页> 外文会议>MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011 >On the efficiency of establishing and maintaining security associations in tactical MANETs in group formation
【24h】

On the efficiency of establishing and maintaining security associations in tactical MANETs in group formation

机译:论战术MANET中组群建立和维护安全关联的效率

获取原文
获取原文并翻译 | 示例

摘要

It has been shown that a Security Association (SA) established by strong authentication between a node pair in a Mobile Ad Hoc Network (MANET) should not depend on link connectivity [1]. While stale (long) SAs should be renewed, SA duration should be managed by a security policy and based on a trust model regardless of link intermittence. Both the security policy and the trust model are modules of a security architecture in [2]. In this paper, we consider nodes in multiple groups using the same channel (one interface) and a hierarchical traffic pattern typical of a tactical operation. We show that the inter-group SAs, between group heads, require a different trust model than that of intra-group SAs if the overhead of authentication is to be kept manageable. We form a new trust model, apply it to the group heads, and adapt their SA duration to their hopped distance away from their authenticators. Our results show that for group heads, the number of hops is a more effective parameter to which their SA duration should be adapted than their actual link distance modeled by FER. Compared to a trust model that adapts to average system FER [2], we show that the new trust model reduces the overhead of authentication for group heads who tend to be multiple hops away from the authenticator. We also show that by relaxing the security policy one can reduce the authentication traffic so that group heads would not be easily detected by the volume of their authentication traffic. Respecting a node's role in a MANET and its traffic pattern, we show the efficiency and flexibility of the security architecture in keeping the overhead low and reducing the probability of role identification by threat of traffic analysis.
机译:已经表明,通过移动自组织网络(MANET)中的节点对之间的强身份验证建立的安全性关联(SA)不应该依赖于链路连接性[1]。尽管应该更新陈旧的(较长的)SA,但是SA持续时间应由安全策略管理,并基于信任模型进行管理,而与链路间歇性无关。安全策略和信任模型都是[2]中安全体系结构的模块。在本文中,我们考虑使用相同通道(一个接口)和战术操作中典型的分层流量模式的多个组中的节点。我们显示,如果要保持可管理的身份验证开销,组负责人之间的组间SA与组内SA所需要的信任模型不同。我们形成一个新的信任模型,将其应用于组长,并使他们的SA持续时间适应其离开验证者的跳跃距离。我们的结果表明,对于组首来说,跳数是比FER建模的实际链路距离更有效的参数,应将其SA持续时间调整为该参数。与适用于平均系统FER [2]的信任模型相比,我们表明,新的信任模型减少了组头的身份验证开销,该组头往往远离身份验证者。我们还表明,通过放宽安全策略,可以减少身份验证流量,因此,很难通过其身份验证流量来检测组头。尊重节点在MANET中的角色及其流量模式,我们展示了安全体系结构的效率和灵活性,可保持较低的开销并通过流量分析的威胁降低角色识别的可能性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号