首页> 外文会议>International Conference on Space Information Technology pt.2 >An authentication framework for a hybrid satellite network with resource-constrained nodes
【24h】

An authentication framework for a hybrid satellite network with resource-constrained nodes

机译:具有资源受限节点的混合卫星网络的认证框架

获取原文
获取原文并翻译 | 示例

摘要

The new phase of space exploration involves a growing number of human and robotic space missions to remote planets with varying communication and service requirements. Due to the critical nature of the missions, security is a very important requirement that needs to be addressed. Among primary security requirements are user authentication and message integrity that are needed to ensure that the data in the network is transmitted without unauthorized modifications between the source and destinations, and that data from only authorized network nodes are accepted by other nodes. In this paper we focus on the issue of user authentication and data integrity for a specific space network architecture supporting lunar exploration. We consider a hybrid network consisting of a terrestrial network on Earth, a network on the lunar surface, and a satellite constellation that connects the two surface networks. The lunar network comprises sensor nodes serviced by stationary gateways and mobile robotic vehicles with sensing capability, while the network on Earth is envisioned as a combination of private and public networks. The problem of authentication in this network is complex due to the presence of nodes with varying capabilities in terms of computation strength, storage and energy. The nodes on Earth and the gateways on the lunar surface would have higher computation and energy capabilities compared to the satellites and the sensor nodes. In this situation, an authentication protocol that is optimized to the strengths and limitations of the different classes of nodes would be most suited. We focus on a solution that will operate under the constraints of the space environment (delay, limited energy, limited processing capability at remote nodes). We present a framework for user authentication and data integrity based on an authentication algorithm that makes use of symmetric certificates and hash chains of keys used to compute Message Authentication Codes, to provide asymmetric authentication capabilities to the network nodes, nodes with more resources. We give a detailed description of the authentication protocol we develop for this network and provide an analysis of the security of the protocol by considering various types of passive and active attacks. We also highlight the savings incurred in terms of processing, storage and network bandwidth, which we get in using the proposed protocol in comparison to standard public-key authentication protocols.
机译:太空探索的新阶段涉及到越来越多的人类和机器人太空飞行任务,它们对通信和服务要求各异的偏远星球进行飞行。由于特派团的关键性质,安全是需要解决的非常重要的要求。在主要的安全要求中,包括用户身份验证和消息完整性,这是确保网络中的数据在源和目标之间未经未经授权的修改的情况下传输以及其他节点仅接受来自授权网络节点的数据所必需的。在本文中,我们重点关注支持月球探测的特定空间网络体系结构的用户身份验证和数据完整性问题。我们考虑一种混合网络,该混合网络由地球上的地面网络,月球表面上的网络以及连接这两个表面网络的卫星星座组成。月球网络包括由固定网关和具有感应功能的移动机器人车辆提供服务的传感器节点,而地球上的网络被设想为私有网络和公共网络的组合。由于存在在计算强度,存储和能量方面具有变化能力的节点,因此该网络中的认证问题很复杂。与卫星和传感器节点相比,地球上的节点和月球表面上的网关将具有更高的计算和能量功能。在这种情况下,最适合于不同类别节点的优缺点的认证协议。我们专注于将在空间环境(延迟,能量有限,远程节点处的处理能力有限)的约束下运行的解决方案。我们提出了一个基于身份验证算法的用户身份验证和数据完整性框架,该身份验证算法利用对称证书和用于计算消息身份验证代码的密钥哈希链来为网络节点(资源更多的节点)提供非对称身份验证功能。我们将详细介绍为该网络开发的身份验证协议,并通过考虑各种类型的被动和主动攻击来对协议的安全性进行分析。我们还着重介绍了在处理,存储和网络带宽方面节省的费用,与标准的公共密钥身份验证协议相比,使用建议的协议可以节省大量费用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号