摘要
3GPP认证密钥交换协议存在两大安全缺陷:(1)该协议假设在VLR和HLR间的通信信道必须是安全的,因而易遭受攻击者接入信道后的主动攻击;(2)该协议对于移动用户易遭受重定向攻击。该文提出了一种新型增强3GPP认证密钥交换协议,克服了原协议的安全缺陷,确保了在不安全的信道上实现安全的通信,同时很好地防止了对于用户的重定向攻击,并且该新型增强协议的实施无须改动3GPP的安全体系结构。
The 3GPP authentication and key agreement has two security shortages. One is that it needs a strong secure channel assumption between the VLR and the HLR, and will easily suffer from the active attack after the adversary accesses the channel. The other is that it easily suffers from the re-direction attack for the users. In this paper, a new enhanced 3GPP authentication and key agreement is proposed to overcome the two security shortages. The new enhanced 3GPP AKA protocol can ensure the secure communication in the insecure channel and defeat the re-direction attack for the users. In addition, it can be implemented without modification of SGPP AKA security architecture.
出处
《计算机工程》
CAS
CSCD
北大核心
2006年第12期147-149,共3页
Computer Engineering
基金
国家"863"计划基金资助项目"网上信息安全综合分析与监控系统"(2003AA142160)