针对3G鉴权与密钥协商协议(3GPP AKA)中存在的安全缺陷,结合攻击者可能发起的攻击提出了一种可以防止重定向攻击,利用存在安全漏洞的网络发起的主动攻击,SQN同步缺陷和用户身份信息泄露的改进协议(ER AKA,Efficient and Robust Authenti...针对3G鉴权与密钥协商协议(3GPP AKA)中存在的安全缺陷,结合攻击者可能发起的攻击提出了一种可以防止重定向攻击,利用存在安全漏洞的网络发起的主动攻击,SQN同步缺陷和用户身份信息泄露的改进协议(ER AKA,Efficient and Robust Authentication and Key Agreement),并对其安全性和效率进行了分析,分析表明通过该协议可以以较少的存储资源和计算资源为代价有效的解决上述安全性问题并减少3G系统中安全性处理的信令交互次数。展开更多
The demand of ubiquitous communications drives the development of advanced mobile technologies. Meanwhile, recent increases in mobile data usage and the emergence of new IP service applications constitute the motivati...The demand of ubiquitous communications drives the development of advanced mobile technologies. Meanwhile, recent increases in mobile data usage and the emergence of new IP service applications constitute the motivation to integrate 3GPP cellular mobile systems with broadband WLANs. Since 3GPP and WLAN systems complement each other in terms of infrastructure and network coverage and bandwidth, 3GPP-WLAN Heterogeneous Mobile Networks based on the 3GPP-based Home Network (3GHN) are proposed for meeting the growing demands in high-speed data access on any mobile devices. However, heterogeneous radio access technologies and architectures lead to many interworking issues, such as network transparency, security mechanism, seamless handover, and quality of service. Among of them, security and handover are the major motives to ensure the confidentiality, reliability and continuity of services in 3GPP-WLAN Heterogeneous Mobile Networks. This paper proposes fast handover pre-authentication protocol to reduce the handover authentication latency and authentication signaling overhead during the whole handover session. The proposed protocol supports Intra-Domain Handover Pre-Authentication (Intra-HO Pre-Auth) and Inter-Domain Handover Pre-Authentication (Inter-HO Pre-Auth) for preauthenticating the Mobile User (MS) prior to performing an Inter-domain Handover (Inter-domain HO)/Intra-domain Handover (Intra-domain HO) process. Meanwhile, the reduction in retrieving new Authentication Vector sand key sets from the Home Location Register/Home Subscriber Service/Authentication Center in 3GHN achieves for minimized redundant authentication signaling transactions between 3GPP domains and WLAN domains. In addition, this paper provides simulation results which show that the proposed Intra-HO Pre-Auth achieves 49% handover authentication performance improvement compared to EAP-AKA, and the proposed Inter-HO Pre-Auth achieves 26% handover authentication performance improvement as well.展开更多
第3代移动通讯系统(3G)与无线局域网(WLAN)的互连,已成为第三代移动通讯合作计划(3GPP)的研究重点。通过分析3G-WLAN互连面临的安全挑战,指出EAP-AKA认证协议在用户身份的暴露、未考虑3G网络端的认证和保密通讯、身份认证的效率不高、...第3代移动通讯系统(3G)与无线局域网(WLAN)的互连,已成为第三代移动通讯合作计划(3GPP)的研究重点。通过分析3G-WLAN互连面临的安全挑战,指出EAP-AKA认证协议在用户身份的暴露、未考虑3G网络端的认证和保密通讯、身份认证的效率不高、业务的不可否认性未得到保障等方面的不足,提出了一种基于公钥与私钥相结合的认证与密钥协商协议(Public And Private Key Based Authentication And Key Agreement,PPK-AKA),并进行了安全性能分析,其有效地解决了EAP-AKA协议存在的安全隐患,提高了系统的安全强度。展开更多
文摘针对3G鉴权与密钥协商协议(3GPP AKA)中存在的安全缺陷,结合攻击者可能发起的攻击提出了一种可以防止重定向攻击,利用存在安全漏洞的网络发起的主动攻击,SQN同步缺陷和用户身份信息泄露的改进协议(ER AKA,Efficient and Robust Authentication and Key Agreement),并对其安全性和效率进行了分析,分析表明通过该协议可以以较少的存储资源和计算资源为代价有效的解决上述安全性问题并减少3G系统中安全性处理的信令交互次数。
文摘The demand of ubiquitous communications drives the development of advanced mobile technologies. Meanwhile, recent increases in mobile data usage and the emergence of new IP service applications constitute the motivation to integrate 3GPP cellular mobile systems with broadband WLANs. Since 3GPP and WLAN systems complement each other in terms of infrastructure and network coverage and bandwidth, 3GPP-WLAN Heterogeneous Mobile Networks based on the 3GPP-based Home Network (3GHN) are proposed for meeting the growing demands in high-speed data access on any mobile devices. However, heterogeneous radio access technologies and architectures lead to many interworking issues, such as network transparency, security mechanism, seamless handover, and quality of service. Among of them, security and handover are the major motives to ensure the confidentiality, reliability and continuity of services in 3GPP-WLAN Heterogeneous Mobile Networks. This paper proposes fast handover pre-authentication protocol to reduce the handover authentication latency and authentication signaling overhead during the whole handover session. The proposed protocol supports Intra-Domain Handover Pre-Authentication (Intra-HO Pre-Auth) and Inter-Domain Handover Pre-Authentication (Inter-HO Pre-Auth) for preauthenticating the Mobile User (MS) prior to performing an Inter-domain Handover (Inter-domain HO)/Intra-domain Handover (Intra-domain HO) process. Meanwhile, the reduction in retrieving new Authentication Vector sand key sets from the Home Location Register/Home Subscriber Service/Authentication Center in 3GHN achieves for minimized redundant authentication signaling transactions between 3GPP domains and WLAN domains. In addition, this paper provides simulation results which show that the proposed Intra-HO Pre-Auth achieves 49% handover authentication performance improvement compared to EAP-AKA, and the proposed Inter-HO Pre-Auth achieves 26% handover authentication performance improvement as well.
文摘第3代移动通讯系统(3G)与无线局域网(WLAN)的互连,已成为第三代移动通讯合作计划(3GPP)的研究重点。通过分析3G-WLAN互连面临的安全挑战,指出EAP-AKA认证协议在用户身份的暴露、未考虑3G网络端的认证和保密通讯、身份认证的效率不高、业务的不可否认性未得到保障等方面的不足,提出了一种基于公钥与私钥相结合的认证与密钥协商协议(Public And Private Key Based Authentication And Key Agreement,PPK-AKA),并进行了安全性能分析,其有效地解决了EAP-AKA协议存在的安全隐患,提高了系统的安全强度。