首页> 外文会议>Internet and Multimedia Systems and Applications >AN AGENT BASED CERTIFICATE REVOCATION SCHEME FOR PUBLIC KEY MANAGEMENT IN MOBILE AND WIRELESS ADHOC NETWORKS
【24h】

AN AGENT BASED CERTIFICATE REVOCATION SCHEME FOR PUBLIC KEY MANAGEMENT IN MOBILE AND WIRELESS ADHOC NETWORKS

机译:基于代理的移动和无线自组织网络中公钥管理的证书撤销方案

获取原文

摘要

The absence of centralized servers in mobile ad hoc networks such as wireless Wi-Fi based and other sensor based networks makes it highly difficult to implement public key infrastructure based security systems. The core entity in a public key infrastructure is 'trust relationships'. Every client which need to authenticate a server (authentication means establishing the fact that the server that the client in communicating with is the actual server what it claims to be) ultimately has to rely a certain entity vouching for the server's authenticity. This entity is called the Certificate Authority. However establishing certificates in non-centralized networks such as wireless ad hoc networks could be highly cumbersome. Many distributed solutions have been proposed to address this problem. An important segment in the design of public key infrastructure is provisions for outdated and misused certificates to be revoked. We postulate that the amount of compromise that any node in an ad hoc network has undergone will be reflected most efficiently by nodes in its immediate neighborhood. Based on this, in this paper we present an agent based solution that gleans misuse information of a certain node to determine if a client can accept the node's certificate or not. Agent based architectures are very useful in establishing intelligence in distributed network. We explore the effect of agents on one of the critical aspects of the Internet (vis-a-vis: network security) which has not embraced agent based models at practical levels. With our experiments we provide a platform where agents can be modeled for security practices over the Internet and practical enterprise organizations.
机译:在移动自组织网络(例如,基于无线Wi-Fi和其他基于传感器的网络)中缺少集中式服务器,这使得实现基于公钥基础结构的安全系统非常困难。公钥基础结构中的核心实体是“信任关系”。每个需要对服务器进行身份验证的客户端(身份验证意味着建立一个事实,即与该客户端通信的服务器就是它声称的实际服务器)最终必须依赖某个实体来证明服务器的真实性。该实体称为证书颁发机构。然而,在诸如无线自组织网络之类的非集中式网络中建立证书可能非常麻烦。已经提出了许多分布式解决方案来解决这个问题。公钥基础结构设计中的一个重要部分是撤销过期和滥用证书的规定。我们假设,ad hoc网络中任何节点所遭受的折衷量将由其紧邻区域中的节点最有效地反映出来。基于此,在本文中,我们提出了一个基于代理的解决方案,该解决方案收集某个节点的滥用信息,以确定客户端是否可以接受该节点的证书。基于代理的体系结构对于在分布式网络中建立智能非常有用。我们探讨了代理对Internet的关键方面之一(相对于网络安全性)的影响,该方面在实际水平上并未包含基于代理的模型。通过我们的实验,我们提供了一个平台,可以在此平台上针对Internet和实际企业组织的安全实践对代理进行建模。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号