节点文献

无线传感器网络广播认证方案研究

An Efficient Broadcast Authentication Scheme for Wireless Sensor Networks

【作者】 朱琪美

【导师】 张世庆; 张西良;

【作者基本信息】 江苏大学 , 测试计量技术及仪器, 2006, 硕士

【摘要】 网络安全技术历来是网络技术的重要组成部分。无线传感器网络由于其部署环境的开放性、资源的有限性,比传统网络更易受到安全方面的威胁。许多应用场合对无线传感器网络安全提出了要求,而认证是网络安全服务一个基本方面,目的是证明节点的身份和消息的来源,是其它安全服务的基础。本文在介绍了无线传感器网络的基本结构及相关概念的基础之上,分析了无传感器网络中的基本安全服务之一——广播认证及用于广播认证的各种基本的密码术算法进行了深入的分析,在此基础之上提出了一种新颖的广播认证方案——基于Merkle散列树的高效的广播认证方案(EBAS)。EBAS方案利用了Merkle散列树的优良特性,极大地减少了传统一次签名的公钥尺寸。EBAS方案采用一包一签名的机制,每个消息包中的签名包含了相应消息完整的认证路径及公钥,接收方接收到了消息包就能立即对其来源、完整性和新鲜性进行验证,消除了μTESLA方案中的认证延迟。EBAS方案具体实现分为三个阶段:密钥生成阶段、签名阶段和认证阶段。本文对每一阶段的实现都进行了详细地描述,并为尽可能地降低能耗对Merkle树的参数进行了优化。在对EBAS方案的安全性能及能耗情况进行理论分析并用Matlab进行了仿真验证后,在TinyOS的仿真器TOSSIM上把EBAS方案和μTESLA方案的进行了比较,对比了这两种方案在DoS攻击和信道损耗存在情况下的认证率和认证延迟,结果表明在两种情况下,EBAS方案在认证率和认证延迟两个方面都有了极大的改善。

【Abstract】 Networks security is the important part of networks technology. Due to the opening of the distribution environment and limited resource, wireless sensor networks receive more attacks than traditional networks. In many applications, higher security requirements for wireless sensor networks have been proposed, broadcast is the base of networks security, the aim is to prove identity of sensors and source of information.In this paper, the concepts, the system structure and the secure problems of wireless sensor networks are introduced firstly. Then we analyze the design goals of secure scheme. As an essential security service in wireless sensor networks, the broadcast authentication is mainly discussed. Accordingly, various cryptographic primitives for broadcast authentication and their present schemes are analyzed. Based on the study above, we propose a novel scheme for broadcast authentication--an efficient broadcast authentication scheme based on the Merkle hash tree.Due to employ the Merkle tree, EBAS scheme greatly reduces the size of public keys of traditional one-time signature. EBAS scheme uses the mechanism that there is one signature in one message packet. The signature of every message contains corresponding authentication path and the public keys, receivers can check the source and veracity of the received messages in time. EBAS scheme removes the authentication delay. EBAS scheme consists of three steps: key generation, signing and verifying. The realization of every step would be described in detail. In order to possibly reduce the overhead, we optimize the parameter of Merkle tree. Finally, compared with the u TESLA scheme under DoS attacks and communication failures, simulation results showed that our technique outperform present schemes in terms of security, authentication rate and storage space.

  • 【网络出版投稿人】 江苏大学
  • 【网络出版年期】2007年 05期
  • 【分类号】TN929.5;TP212.9;TN934
  • 【被引频次】8
  • 【下载频次】245
节点文献中: 

本文链接的文献网络图示:

本文的引文网络