
基于本地安全关联的移动网络接入认证机制 被引量:1

Authentication mechanism for network mobility based on local security associations
摘要 为减少网络移动中身份认证对性能的影响,提出了一种基于本地安全关联的接入认证机制。该机制通过认证消息携带地址注册信息,整合认证和绑定更新过程,采用本地移动性管理策略,通过建立本地安全关联,实现了域内切换流程本地化,保护了地址注册信息,避免了隧道嵌套。性能分析表明,该机制在实现双向认证的同时能够抵抗重放等多种攻击,相比其他方案,该机制减小了计算开销,缩短了切换时延。 In order to reduce the impact of identity authentication on performance of network mobility,this paper introduced an authentication mechanism.In the mechanism,integrated the authentication and binding update procedures by adding address registration information into authentication messages.With the help of local mobility management strategy and local security associations,the mechanism localized the message flow of the intra-domain handoff,protected the address registration information and eliminated the tunnel-in-tunnel problem.Analysis shows that,the mechanism not only implements the mutual authentication but also resists various attacks such as modified attack.The proposed solution outperforms the counterparts in terms of the computation cost and handoff latency.
出处 《计算机应用研究》 CSCD 北大核心 2012年第5期1896-1900,共5页 Application Research of Computers
基金 国家科技重大专项资助项目(2009ZX03004-002)
关键词 网络移动性 认证、授权、计费 本地认证 快速切换 network mobility(NEMO) authentication、authorization、accounting(AAA) local authentication fast handoff
  • 相关文献


  • 1DEVARAPALLI V,WAKIKAWA R,PETRESCU A,et al.RFC3963,network moblity(NEMO)basic support protocol[S].[S.l.]:IETF,2005.
  • 2CHUANG M C,LEE J F.A lightweight mutual authentication mecha-nism for network mobility in IEEE 802.16e wireless networks[J].Computer Networks,2011,55(16):3796-3809.
  • 3LIM H J,KIM M,LEE J H,et al.Reducing communication over-head for nested NEMO networks:roaming authentication and accesscontrol structure[J].IEEE Trans on Vehicular Technology,2011,60(7):3408-3423.
  • 4FATHI H,SHIN S,KOBARA K.R-AKE-based AAA for networkmobility(NEMO)over wireless links[J].IEEE Journal on Selec-ted Areas in Communications,2006,24(9):1725-1737.
  • 5AHN Y,LEE T J,CHOO H,et al.DNA Diameter NEMO applica-tions based on binding update integration[C]//Proc of Frontiers ofHigh Performance Computing and Networking.Berlin:Springer-Ver-lag,2006:1-6.
  • 6SOLIMAN H,CASTELLUCCIA C,ELMALKI K,et al.RFC 5380,hierarchical mobile IPv6(HMIPv6)mobility management[S].[S.l.]:IETF,2008.
  • 7JAYARAMAN P,LOPEZ R,OHBA Y,et al.RFC 5193,protocolfor carrying authentication for network access(PANA)framework[S].[S.l.]:IETF,2008.
  • 8KORHONEN J,BOURNELLE J,TSCHOFENIG H,et al.RFC5447,Diameter mobile IPv6:support for network access server todiameter server interaction[S].[S.l.]:IETF,2009.
  • 9NIST.Department of Commerce.Federal Information ProcessingStandard(FIPS),secure hash standard[S].2002.
  • 10PETRESCU A,OLIVEREAU A,JANNETEAU C,et al.Draft-pe-trescu-nemo-threats-01,threats for basic network mobility support(NEMO threats)[S].[S.l.]:IETF,2004.


  • 1Johnson D, Perkins C, and J Arkko. Mobility Support in IPv6 [S]. IETF RFC 3775, June 2004.
  • 2WiMAX End-to-End Network Systems Architecture, (Stage 2: Architecture Tenets, Reference Model and Reference Points) [OL]. http://www. wimaxforum. org/technology/documents, 2007.
  • 33GPP, 3GPP system architecture evolution (SAE): Report on technical options and conclusions [S].3GPP TR 23.882 0.10. 1, February 2006.
  • 4S Gundavelli, K Leung, V Devarapalli, K Chowdhury and B Patil. Proxy Mobile IPv6 [ S ]. IETF draft-ietf-netlmm-proxymip6-00, April 2007.
  • 5C Perkins, P Calhoun and J Bharatia. Mobile IPv4 Challenge/ Response Extensions (Revised) [S ]. IETF RFC 4721, January 2007.
  • 6Wei Liang and Wenye Wang. On performance analysis of challenge/respons based authentication in wireless local area networks [ J ]. In Computer Networks (Elsevier), 2005,48 ( 2 ) : 267 - 288.
  • 7Calhoun P, Loughney J, Guttman E, Zom G, and J Arkko. Diameter Base Protocol [S]. IETF RFC 3588, September 2003.
  • 8P Calhoun, T Johansson, C Perkins, T Hiller, Ed. P McCann. Diameter mobile IPv4 application [A ]. IETF RFC 4004 [ C ], August 2005.
  • 9Franck Le, Basavaraj Pafil, Charles E. Perkins, Stefano Faccin, Diameter Mobile IPv6 Application [ S ]. IETF draft-le-aaa-diameter- mobileipv6-04, Nov. 2004.
  • 10Sungmin Baek, Sangheon Pack, Taekyoung Kwon, and Yanghee Choi. A localized authentication, authorization, and accounting (AAA) protocol for mobile hotspots [A ]. In Proc. IEEE/IFIP Annual Conference on Wireless On demand Network Systems and Services ( WONS ) 2006[ OL ]. http://citi. insa-lyon.fr/wons2006/Articles/17-Baek. pdf, Les Menuires, France, January 2006.












使用帮助 返回顶部