摘要
针对3GPP AKA协议中存在的安全缺陷,在消息中加入访问网络的身份信息,利用秘密令牌机制,提出了一种可以防止重定向攻击、SQN同步缺陷和用户身份信息泄露的改进方案,并对其安全性和效率进行了分析。分析表明,本方案可以有效解决上述问题,以较少的资源开销就能获取协议效率和安全性能的提高。
Considering the security of the 3 GPP authentication and key agreement (AKA) protocol, an improved scheme is proposed to prevent the redirection attack, the flaw of SQN synchronization and leak of user' s identity information by adding the identity of VLR and utilizing the secret token scheme. The security and efficiency of the proposed scheme is analysed. The analysis shows that the proposal can effectively solve the problems mentioned above, improve the security and the efficiency of the protocol with little resource cost.
出处
《电讯技术》
2008年第11期19-23,共5页
Telecommunication Engineering
基金
国家高技术研究发展计划(863计划)项目(2007AA01Z434)
关键词
网络安全
3GPP
AKA
认证
密钥协商
身份保护
network security
3 GPP AKA
authentication
key agreement
identity protection