节点文献

面向无线漫游服务的轻量级匿名安全认证协议研究

Research on Lightweight Anonymous Security Authentication Protocol on Wireless Roaming Service

【作者】 杨斌

【导师】 许光全; 陈列伟;

【作者基本信息】 天津大学 , 软件工程, 2018, 硕士

【摘要】 随着移动设备的快速发展,移动应用的数量和质量的不断提高,用户对移动网络的覆盖面积和服务质量的要求日益增高。然而,仅靠网络设备的层层堆叠来扩大覆盖面积和服务质量的方法成本巨大,因此,无线漫游服务(Wireless Roaming Service)技术应运而生,该技术可以支持用户不受地理位置的限制,在不同的网络管区之间享受无差别的无线网络服务。虽然无线漫游过程中的安全问题得到了一些研究者的关注,但是仍然存在一些问题没有解决。攻击者往往在未经授权的情况下,实现对数据或服务的非法访问,从而影响整个无线漫游服务质量,甚至泄露用户隐私,对用户造成不法侵害。然而,鉴于移动设备相对有限的电量和较低的计算能力,传统的认证协议并不能适应无线漫游网络。为了解决上述问题,本文对随机预言机模型(Random Oracle Model)进行了改进,重新描述了攻击者的攻击手段和攻击能力,提出了更加完善的安全需求,定义了一个新的数学模型,该模型更加适合无线漫游认证协议的安全性证明。在此基础上,本文基于该模型提出了一个基于口令的轻量级无线漫游认证协议。该协议采用轻量级加密技术 ECDSA,在有限域Fp中构建满足y2=(x3+ax+b)mod p条件的椭圆曲线群Ep(a,b),生成用于签名的公私钥对,来为通信实体间传输的消息提供不可抵赖性和不可伪造性。同时,该协议应用伪随机身份信息技术(Pseudo-Random-Identity)来保护用户的匿名性和不可追踪性。最后,本文给出了该协议在新模型下的安全性证明,以及与其他具有代表性的无线漫游协议在安全属性以及计算消耗两方面的对比分析。本文提出的安全模型可协助相关协议进行安全性形式化证明,对无线漫游认证协议的研究具有一定意义。同时,通过分析和实验比较,本文提出的协议安全性高,在保证安全建立会话密钥的前提下,可以最大化的减少用户端的计算开销,保护用户的隐私不受侵犯。

【Abstract】 With the rapid development of the mobile devices,the users’ demands of the coverage area and quality of service of mobile networks are increasing day by day.However,the cost of the way to expand coverage and quality of service by increasing the quantity of the network devices is enormous.Therefore,wireless roaming service technology emerges as the times require.This technology can support users to enjoy undifferentiated wireless network services between different network management areas without geographical restrictions.Although some researchers have paid attention to the security problems in the process of wireless roaming during this years,there are still some unsolved problems.Attackers often access data or services illegally without authorization,thus affecting the quality of wireless roaming services,or even revealing user privacy and causing unlawful infringement on users.However,due to the relatively limited power and low computing power of mobile devices,traditional authentication protocols can not adapt to wireless roaming networks.In order to solve the above problems,we improved the Random Oracle Model and re-described the attack means and the ability of the attackers,and we put forward a more perfect security requirement.Meanwhile,a new mathematical model is defined.This model is more suitable for the security proof of wireless roaming authentication protocol.Based on this model,we propose a password-based lightweight wireless roaming authentication protocol.The protocol uses ECDSA,a lightweight encryption technology,which to construct elliptic curve groups y2=(x3 + ax + b)mod p satisfying the conditions in the finite field Fp to generate public-private key pairs for signature to provide non-repudiation and non-forgery for messages transmitted between communication entities.At the same time,the protocol uses Pseudo-Random-Identity to protect the anonymity and traceability of users.Finally,the security proof of the protocol under the new model is given and we compared our protocol with other representative wireless roaming protocols in terms of security attributes and computational cost.The security model proposed in this paper can assist the formal proof of the security of the related protocols,which is of great significance to the research of wireless roaming authentication protocols.At the same time,through analysis and experimental comparison,the proposed protocol has high security attributes.On the premise of guaranteeing the safe establishment of session key,it can minimize the computing costs overhead of the user and protect the privacy of the users.

  • 【网络出版投稿人】 天津大学
  • 【网络出版年期】2020年 06期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络