首页> 外文会议>International Conference on Multimedia Information Networking and Security >Optimizing PKI for 3GPP Authentication and Key Agreement
【24h】

Optimizing PKI for 3GPP Authentication and Key Agreement

机译:优化3GPP身份验证和密钥协议的PKI

获取原文

摘要

Authentication and key agreement (AKA) is one of the key security mechanisms in the Third Generation (3G) telecommunication. Contrast to the traditional symmetric encryption based 3G AKA scheme, this paper proposes a PKI based AKA scheme named OPAKA. To minimize performance overheads that normal PKI certificate verification incurs, OPAKA introduces a novel notion of certificate validity ticket (CVT), which is created by home network (HN) of mobile equipment (ME), indicating whether the certificate of the visited network (VN) is valid. Because CVT is sealed by the pre-shared secret between ME and HN and ME trusts HN, VN can attest its identity to ME by presenting CVT to ME. Thus relieves ME from verifying the certificate of VN online. It's argued that OPAKA can achieve the security goals of denying unauthorized ME, protecting ME from fake VN, and allowing mutual authentication between VN and HN. Compared with SPAKA and Lee's Scheme, OPAKA incurs less communication and computation overhead at both ME and HN ends.
机译:身份验证和密钥协议(AKA)是第三代(3G)电信中的关键安全机制之一。与传统的对称加密的3G AKA方案对比,本文提出了一种名为Opaka的PKI基于的AKA方案。为了最大限度地减少正常的PKI证书验证的性能开销,opaka引入了一种新颖的证书有效性票据(CVT)概念,由移动设备(ME)的家庭网络(HN)创建,指示访问网络的证书(VN ) 已验证。因为CVT由我和HN之间的预共同秘密密封,我信任HN,VN可以通过向我呈现CVT来证明其身份。因此,减轻了我验证VN在线证书。据称,Opaka可以实现否认未经授权的安全目标,保护我免受假VN,并允许VN和HN之间的相互认证。与Spaka和Lee的计划相比,Opaka在ME和HN结束时遭到更少的沟通和计算开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号