上海交通大学学报(自然版) ›› 2014, Vol. 48 ›› Issue (10): 1491-1497.

• 自动化技术、计算机技术 • 上一篇    下一篇

PMIPv6中基于安全关联的移动网络本地轻型认证机制

汤红波1,唐伟1,2,陈龙1   

  1. (1.国家数字交换系统工程技术研究中心,郑州 450002;2.中国人民解放军72556部队,济南 250306)
  • 收稿日期:2013-12-20
  • 基金资助:

    国家重点基础研究发展计划(973)项目(2012CB315901),国家科技重大专项课题(2013ZX03006002006)资助

A Lightweight Local Authentication Mechanism for Network Mobility in Proxy Mobile IPv6 Network Based on Security Associations

TANG Hongbo1,TANG Wei1,2,CHEN Long1   

  1. (1. National Digital Switching System Engineering & Technological R & D Center, Zhengzhou 450002, China; 2. PLA 72556, Jinan 250306, China)
  • Received:2013-12-20

摘要:

摘要:  针对PMIPv6域中移动网络(NEMO)提出了一种基于安全关联的本地轻型认证机制.该机制在认证、授权和计费(AAA)架构的基础上,整合身份认证和地址注册过程,采用优化的切换策略和扩展的安全关联,将切换和认证过程限定在本地PMIPv6域中.性能分析表明,该机制在实现用户和网络之间双向认证的同时能够抵抗篡改等多种攻击,有效保护地址注册信息,提升NEMO的安全性,并在计算开销和认证时延方面优于现有机制.

关键词: 网络移动性, 代理移动IPv6, 认证, 切换

Abstract:

Abstract: A local light authentication mechanism based on security associations (LLAMSA) for network mobility (NEMO) in Proxy Mobile IPv6 Network was proposed. Based on the architecture of authentication, and authorization and accounting (AAA), the mechanism of optimized routing policy and extended security association was used to integrate authentication and address registration process, making the handover and authentication process to be limited in the local PMIPv6 domain. The performance analysis shows that LLAMSA not only implements the mutual authentication but also resists tamper attacks to protect the address registration information, improving the safety of NEMO. The performance of computation cost and authentication delay is better than existing mechanisms.

Key words: network mobility (NEMO), Proxy Mobile IPv6 (PMIPv6), authentication, handoff

中图分类号: