首页> 外文会议>IEEE 7th International Conference on Mobile Adhoc and Sensor Systems >A modular security architecture for managing security associations in MANETs
【24h】

A modular security architecture for managing security associations in MANETs

机译:用于管理MANET中的安全关联的模块化安全体系结构

获取原文

摘要

Maintaining security associations (SA) in mobile ad hoc networks (MANET) is challenging due to their intrinsically open, dynamic, and decentralized nature. Bandwidth limitations arising from both the physical characteristics of the wireless medium and the control overhead required to maintain routes in a network with changing topology add another level of difficulty to the problem. While establishing SAs with strong authentication is a generally accepted practice, the allowed duration of these SAs is a harder problem that may depend on a number of factors. Ideally, we would like to optimize the maintenance of the SAs to balance quality of protection (QoP) against quality of service (QoS). In this paper we propose and describe a modular security architecture to achieve this goal. The architecture consists of security policy, trust model, and state machine modules that together control the strong authentication process for establishing and maintaining SAs. We demonstrate the efficacy of this architecture through simulation of a MANET that implements a Trust-enhanced Routing Table (TRT). Our simulations use a state machine to manage the authentication process linked to a TRT previously proposed as a security extension of the optimized link state routing (OLSR) protocol. We demonstrate that this state machine, when linked to an adaptive trust model itself controlled by a security policy, can substantially outperform static models. Because the architecture is modular, the implementation can be tailored for different environments or scenarios.
机译:由于移动自组织网络(MANET)本质上是开放的,动态的和分散的,因此在移动自组织网络(MANET)中维护安全性协会(SA)具有挑战性。由无线介质的物理特性和在拓扑变化的网络中维护路由所需的控制开销所引起的带宽限制,给问题增加了另一个难度。虽然通过强身份验证建立SA是一种普遍接受的做法,但是这些SA的允许持续时间是一个较难的问题,可能取决于许多因素。理想情况下,我们希望优化SA的维护,以在保护质量(QoP)和服务质量(QoS)之间取得平衡。在本文中,我们提出并描述了实现此目标的模块化安全体系结构。该体系结构由安全策略,信任模型和状态机模块组成,它们一起控制用于建立和维护SA的强大身份验证过程。我们通过模拟实现信任增强路由表(TRT)的MANET证明了该体系结构的有效性。我们的仿真使用状态机来管理链接到TRT的身份验证过程,该TRT先前被建议为优化链接状态路由(OLSR)协议的安全扩展。我们证明了,当这种状态机链接到本身由安全策略控制的自适应信任模型时,其性能将大大优于静态模型。由于该体系结构是模块化的,因此可以针对不同的环境或场景量身定制实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号