摘要
为了降低移动ad hoc网络非对称密钥管理中的通信开销,基于组合公钥思想,将ElGamal方案与预分配密钥方式相结合,提出一种基于身份的预分配非对称密钥管理方案(PAKMS)。该方案通过私钥生成中心为节点预分配主密钥子集及基于时间获得节点密钥更新的方式,从方法上降低了移动ad hoc网络非对称密钥管理中的通信开销;私钥生成中心为节点预分配主密钥子集的方式也使节点在网络运行阶段不再依赖私钥生成中心为节点分配和更新密钥。由此,弱化了基于身份密钥管理中存在的私钥托管问题对网络安全的影响。与典型方案对比分析表明,该方案在提供节点密钥更新服务的情况下能够有效降低网络通信开销。此外,对方案的安全性进行了详细证明。
In order to reduce communication overhead of the asymmetric key management in mobile ad hoc networks, an identity-based pre-distribution asymmetric key management scheme (PAKMS) was presented based on combined public key (CPK) framework, ElGamal public key cryptosystem and key pre-distribution mode. This scheme essentially reduced communication overhead of the asymmetric key management in mobile ad hoc networks by the private key generation (PKG) distributing a subset of master key for every node beforehand and a time-based key update approach. The method that PKG pre-distributed a subset of master key also made the nodes obtain their keys and key update services, which did not need to rely on online PKG. Thus, the inherent key escrow problem existing in identity-based asymmetric key man- agement was avoided to some degree. Compared with typical schemes, this scheme needed much less communication overhead to accomplish node key update service. Furthermore, security proof of the scheme was described in detail.
出处
《通信学报》
EI
CSCD
北大核心
2012年第10期26-34,共9页
Journal on Communications
基金
国家自然科学基金资助项目(60973112)
中央高校基本科研专项基金资助项目(2011JBM031)~~
关键词
移动AD
HOC网络
安全
预分配
基于身份的密钥管理
通信开销
mobile ad hoc network
security
pre-distribution
identity-based key management
communication overhead