首页> 外文OA文献 >A comprehensive security architecture for multi-operator wireless mesh networks
【2h】

A comprehensive security architecture for multi-operator wireless mesh networks

机译:适用于多运营商无线网状网络的全面安全架构

摘要

Wireless Mesh Networks (WMNs) represent one of the key technologies that are used to cope with the increasing demand of ubiquitous connectivity and the accompanying hunger for bandwidth. Due to their wireless nature WMNs are very flexible in their deployment. However, flexibility often comes at the price of security. WMNs have to be secured against external, as well as against internal attackers. Special attention has to be paid to all communication patterns in the network, since otherwise no comprehensive security can be achieved. This thesis proposes a comprehensive security architecture for WMNs that ex- tends standardized mechanisms such as the Extensible Authentication Protocol (EAP), the Remote Dial-in User Service (RADIUS), IEEE 802.11i, and the Internet Protocol Security (IPsec) suite. We compose an architecture that allows to bootstrap secu- rity associations based on an extensible key hierarchy. Besides enabling secure communication between authenticated devices, our architecture is generalized to support multi-operator scenarios. This also includes completely new concepts such as mixed-networks in which network operators cooperate in running a converged network. Our comprehensive security architecture is augmented by handover pro- tocols that enable network clients, but also the network infrastructure, to hand over from one point of network attachment to the next. The complete architecture has also been evaluated using a live, custom-built WMN testbed based on off-the-shelf hardware. This underlines the feasibility and practicality of the work put forth in this thesis.
机译:无线网状网络(WMN)代表了一种关键技术,用于应对日益增长的无处不在的连接以及随之而来的对带宽的需求。由于其无线特性,WMN的部署非常灵活。但是,灵活性通常是以安全为代价的。必须保护WMN不受外部和内部攻击者的攻击。必须特别注意网络中的所有通信模式,因为否则无法获得全面的安全性。本文提出了一种用于WMN的综合安全体系结构,该体系结构扩展了标准化机制,例如可扩展身份验证协议(EAP),远程拨入用户服务(RADIUS),IEEE 802.11i和Internet协议安全性(IPsec)套件。我们构建了一种架构,该架构允许基于可扩展的密钥层次结构来引导安全性关联。除了支持经过身份验证的设备之间的安全通信外,我们的体系结构还被通用化以支持多运营商方案。这还包括全新的概念,例如混合网络,网络运营商可以在其中运行融合网络。切换协议增强了我们全面的安全体系结构,该协议使网络客户端以及网络基础架构能够从一个网络连接点切换到另一个网络连接点。完整的体系结构也已使用基于现成硬件的现场定制WMN测试平台进行了评估。这突出了本文提出的工作的可行性和实用性。

著录项

  • 作者

    Egners André;

  • 作者单位
  • 年度 2015
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号