节点文献

无线Mesh网络路由的安全扩散机制研究

Study on Routing Security Diffusion Mechanism in Wireless Mesh Network

【作者】 李伟华

【导师】 沈波;

【作者基本信息】 北京交通大学 , 信息网络与安全, 2013, 硕士

【摘要】 摘要:无线Mesh网络是一种自组织、多跳的无线网络,由于其部署简便,近几年来发展迅速。但是由于无线和路由多跳等特性,无线Mesh网络路由很容易受到各种各样的攻击,其又面临着严峻的安全挑战。一方面由于无线媒质的共享性,攻击者可以窃听网络中路由器之间的通信或注入虚假的路由信息,另一方面由于路由的多跳特性,对攻击行为的检测变得更加困难。路由的安全成为了无线Mesh网络研究的一个重要方向。为了保护无线Mesh网络路由的安全,要对路由节点进行认证,保证路由信息是来自合法的节点。在目前的认证方案中,通常是在网络中部署一个认证服务器来提供认证服务,但是在分布式的无线Mesh网络中,集中式的认证服务器会变成脆弱的攻击点,易产生单点失效问题。为克服集中式认证服务的弊端,有人提出了适合于分布式网络的门限认证方案,CA将认证私钥分散给多个节点,而由其中的门限值个认证节点来发布数字证书来实现认证功能。本文根据门限认证思想和密码学知识设计了一个适合无线Mesh网络的分布式认证方案。另外,为了保护路由信息的安全,需要部署合适的群密钥管理机制,但目前密码学上的群密钥管理方案并不适合无线Mesh网络的结构。μBD群密钥方案需要网络节点有固定的邻居节点,限制了网络的灵活性。μ CLIQUES群密钥方案要求网络节点在群密钥协商时按照顺序依次进行计算,群密钥协商的效率较低。本文利用密码学原理在原有方案上进行改进,提出了一种简单有效的群密钥管理方案。本文通过BAN逻辑对认证方案和群密钥方案进行形式化分析,证明方案中的步骤能够达到预期的目标,并利用OPNET对方案进行仿真,从仿真结果可以得出方案在无线Mesh网络具有一定的适用性。

【Abstract】 ABSTRACT:Wireless mesh network is a self-organized and multi-hop wireless network and recently has a fast development due to its rapid deployment. However, the wireless and distributed natures of WMNs make them subject to various kinds of attacks, which raise a serious challenge in securing these networks. On the one hand, because of the sharing of wireless medium, an attacker can intercept the communication between the routers and even inject false routing information in the networks; on the other hand, due to the characteristics of multiple routing jumps the detection to aggressive behavior becomes more difficult. Routing security in the wireless mesh network has become an important research field.In order to protect the routing security in the wireless mesh network, it needs the authentication on the routing nodes to guarantee the security of routing information. In the present authentication scheme, it usually deploys a the authentication server to provide the authentication service, but in distributed wireless mesh network, the centralized authentication server will becomes a weak point causing the single-point failure problem. To overcome the disadvantages of centralized authentication scheme, someone propose the threshold authentication scheme for distributed network, CA scattered the private key of authentication to nodes, and a certain number of authentication node can provide the authentication service. According to the threshold authentication and cryptography, the thesis designs adistributed authentication scheme for the wireless mesh networks. In addition, in order to protect the security of the routing information, it needs to deploy the suitable group key management scheme, but the current cryptography of group key management scheme is not suitable to wireless mesh network. μBD group key scheme requires that network node has fixed neighbor nodes that limit the deployment of network. μCLIQUES group key scheme requires the fixed order of calculating the group key that has a lower efficiency. The thesis makes the improvement on the current group key scheme by cryptography.The thesis analyses the two schemes formally by BAN logic to prove the correctness of the steps of schemes and simulates them by OPNET to show that they have certain degree feasibility in the wireless mesh network.

【关键词】 WMN认证群密钥BAN逻辑OPNET
【Key words】 WMNAuthenticationGroup KeyBAN LogicOPNET
  • 【分类号】TN929.5
  • 【下载频次】42
节点文献中: 

本文链接的文献网络图示:

本文的引文网络