节点文献
基于用户隐私保护的EAP-AKA协议
EAP-AKA protocol with robust user privacy protection
【摘要】 对3GPP-WLAN采用的认证和密钥协商协议的过程和安全性进行了分析,指出协议的安全缺陷和可能受到的攻击,特别是攻击者采用地址攻击时用户身份会暴露,并且协议存在重定向攻击。针对协议存在的安全问题,提出了一种新的分配方案,但有别于复杂的公钥体制,克服了明文传送IMSI的缺陷,实现了对WLAN-AN的认证以及网络端信息传输的安全性。最后对改进协议进行基于串空间模型的认证测试。
【Abstract】 The procedure and security of the authentication and key agreement protocol adopted by 3GPP-WLAN are analyzed,and the vulnerability and attacks for the protocol is presented,especially,the identity of the user will be exposed when the adversary carries out the location privacy attack,and there exists the redirection attack in the protocol. To solve such security problems for the protocol,a new authentication and key agreement protocol is presented,different from the complicated public key scheme,which overcomes the drawbacks of transferring the IMSI(international mobile station identity) by plaintext,and achieves authentication of WLAN-AN and secure transfer of message between WLAN-AN to HSS. Finally,an authentication test verification based on the strand space model is made.
【Key words】 3GPP-WLAN; authentication protocol; key agreement; strand space model; authentication test;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2009年12期
- 【分类号】TN925.93
- 【被引频次】1
- 【下载频次】123