节点文献

无线局域网密钥分发的研究

Research of Wireless Local Area Network’s Key Distribution

【作者】 刘涛

【导师】 文远保;

【作者基本信息】 华中科技大学 , 计算机系统结构, 2004, 硕士

【摘要】 无线局域网原有的安全体系框架在接入控制、用户身份认证及数据加密三方面存在诸多的安全漏洞,比如:服务集表示符接入控制及身份认证机制脆弱;有线等效加密协议在数据加密和信息完整性方面也存在的问题,使得它不能达到其设计时的目标。同时,缺少有效的密钥管理机制也是无线局域网现有安全体系在设计上的一个盲点。目前有两种主要的无线局域网安全技术:虚拟专用网和802.1x。虚拟专用网由于在漫游及切换过程中存在中断链接、影响业务连续性等问题,使得其在无线局域网中的应用受到一定的局限。802.1x协议由于其体系框架灵活、能够更好地适应新的认证方法等优点,使得它能够更好地适应无线局域网的安全要求。802.11i工作组在将802.1x用于无线局域网中做了大量的工作,并提出了新的无线局域网安全体系框架-强安全网络。强安全网络弥补了无线局域网在密钥管理上的空白,提出了两种密钥体系:双方密钥体系和组播密钥体系。并且分别使用四次握手协议及组播密钥握手协议来实现两种密钥的分发。但这两种密钥管理协议的引入增加了无线局域网在漫游过程中的时延,影响无线局域网漫游过程中的服务质量。在保证密钥分发安全性的前提下,可以通过两点来减小密钥分发带来的时延:其一是将密钥的分发的开始阶段从身份认证结束以后提前到身份认证开始之前,在关联阶段就开始密钥的分发;其二是将组播密钥的分发加入到双方临时密钥的分发过程中,不再进行单独地组播密钥分发。这两点改进有助于减少强安全网络在漫游中由密钥分发所引起的时延,并且保持了对强安全网络的密钥体系及密钥分发协议的兼容性。

【Abstract】 The old secure framework of Wireless Local Area Network has many problems in three aspects: access control, authentication and algorithm of data encryption, such as:flimsiness of mechanism of Service Set Identity control and authentication ,and the data encryption and integrality of Wired Equivalent Privacy has some secure problems, so that its design goal can’t be achieved. Furthermore, lack of effective key management is a blind spot of its secure design.Presently, there are two main secure technology of Wireless Local Area Network:Virtual Private Network and 802.1x. The application of Virtual Private Network in Wireless Local Area Network has been limited, because the interrupt of Virtual Private Network link influences continuity of operation in roaming and handoff case. 802.1x protocol is suitable for Wireless Local Area Network, because of its flexibility and adaptability for new authentication method. IEEE 802.11i work group has engaged in many researches of application of 802.1x protocol. And they put forward a new generation of secure framework, named Robust Security Network.Robust Security Network has made up blankness of the key management. And it includes two key hierarchy:pairwise key hierarchy and group key hierarchy. 4-way handshake and group key handshake protocol are used to distribute the two kinds of key. But the introduction of the two protocols makes delay of roam bigger. And quality of service in roam is played down. There are two measures to reduce it. First, the start point of key distribution is advanced from behind authentication to before authentication. The key distribution starts from association. Second, the group key distribution is joined into pairwise key’s distribution. The individual process of group key’s distribution is cancelled. These improved measures are in favor of reducing the delay in roaming case. And the compatibility of them for Robust Security Network’s protocol of key distribution is kept.

  • 【分类号】TN925.93
  • 【被引频次】4
  • 【下载频次】284
节点文献中: 

本文链接的文献网络图示:

本文的引文网络