首页> 外文期刊>IEEE transactions on wireless communications >TUA: A Novel Compromise-Resilient Authentication Architecture for Wireless Mesh Networks
【24h】

TUA: A Novel Compromise-Resilient Authentication Architecture for Wireless Mesh Networks

机译:TUA:一种用于无线网状网络的新颖的,具有恢复能力的身份验证架构

获取原文
获取原文并翻译 | 示例

摘要

User authentication is essential in service-oriented communication networks to identify and reject any unauthorized network access. The state-of-the-art practice in securing wireless networks is based on the authentication, authorization and accounting (AAA) framework where one or multiple identical and duplicated AAA servers are adopted to authenticate mobile users (MUs), handle authorization requests, and collect accounting data. However, the conventional AAA framework cannot tolerate a server compromise event due to misuse, misconfiguration, and malicious access, etc., which may cause serious damages and resource abuses to the network operation. In this paper, we propose a novel design paradigm toward a compromise-resilient authentication architecture in service-oriented wireless mesh networks (WMNs) based on the (t, n) threshold signature technique, termed Threshold User Authentication (TUA) scheme. With the TUA scheme, only t or more out of n AAA servers in the WMN can cooperatively grant the network access to a MU, while any t-1 or less cannot. Detailed protocol-aspect design and implementations are presented. Extensive analysis on efficiency and reliability of authentication functionality is conducted to gain a deeper understanding on the parameter settings and optimization, which demonstrates the effectiveness of the TUA scheme. We conclude that the proposed authentication scheme can contribute to the WMN network design in metropolitan areas where numerous mesh points (MPs) coexist and are managed under a single control plane with multiple distributed AAA servers.
机译:在面向服务的通信网络中,用户身份验证对于识别和拒绝任何未经授权的网络访问至关重要。确保无线网络安全的最新技术是基于身份验证,授权和计费(AAA)框架的,其中采用了一个或多个相同且重复的AAA服务器来验证移动用户(MU),处理授权请求和收集会计数据。但是,传统的AAA框架不能容忍由于滥用,配置错误和恶意访问等导致的服务器危害事件,这可能会导致严重的损害和网络操作的资源滥用。在本文中,我们提出了一种基于(t,n)阈值签名技术的面向服务的无线网格网络(WMN)中的折衷弹性身份验证体系结构的新颖设计范例,称为阈值用户身份验证(TUA)方案。使用TUA方案,在WMN中,只有n个AAA服务器中的t个或更多可以协作地向MU授予网络访问权限,而任何t-1或更少的则不能。介绍了详细的协议方面的设计和实现。对身份验证功能的效率和可靠性进行了广泛的分析,以更深入地了解参数设置和优化,从而证明了TUA方案的有效性。我们得出的结论是,提出的身份验证方案可以为大面积区域中的WMN网络设计做出贡献,在该区域中,多个网格点(MP)共存,并在具有多个分布式AAA服务器的单个控制平面下进行管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号