一种安全的集群无线网络环境下密钥协商协议
网络出版日期: 2025-01-25
基金资助
国家自然科学基金(62472438, 62172433);河南省自然科学基金(242300421414)
版权
A secure key agreement protocol in clustered wireless network environment
Online published: 2025-01-25
Copyright
集群无线网络作为物联网的一种应用领域,通常部署于不安全的环境,容易遭受网络攻击和利用。近年来,随着集群无线网络环境的研究逐渐增多,适用于集群无线网络环境的认证密钥协商协议应运而生。但是由于集群无线网络本身具有能源消耗高、计算复杂、传输效率低等特点,现有的密钥协商协议难以满足上述需求,同时多数协议仍存在一定的安全问题。为了解决上述问题,基于IBAKAS(Identity-Based Authentication and Key Agreement Scheme)协议提出了一种集群无线网络环境下密钥协商协议,并给出了协议的可证明安全、BAN逻辑分析和Scyther形式化分析。此外,将改进后的协议与其他同类型协议进行性能对比。结果表明,新协议不仅安全可行,而且具有高效的计算效率和通信效率,满足了集群无线网络环境的工作要求。
关键词: 集群无线网络; 认证密钥协商协议; 可证明安全; BAN逻辑分析; Scyther形式化分析
尹日升 , 刘潇 , 马永柳 , 杜宜宾 , 程庆丰 . 一种安全的集群无线网络环境下密钥协商协议[J]. 网络空间安全科学学报, 2024 , 2(5) : 57 -66 . DOI: 10.20172/j.issn.2097-3136.240505
As an application field of the internet of things, clustered wireless networks are usually deployed in insecure environments and are vulnerable to network attacks and exploitation. In recent years, with the increasing research on clustered wireless networks environment, the authentication and key agreement protocol which is suitable for clustered wireless networks environment comes into being. However, due to the inherent characteristics of clustered wireless networks such as high energy consumption, complex computation, and low transmission efficiency, the existing key agreement protocols are difficult to meet the requirements. Moreover, most of these protocols still have certain security issues. To solve the above problems, a key agreement protocol based on the IBAKAS (Identity-Based Authentication and Key Agreement Scheme) protocol in clustered wireless networks was proposed by this article, which provided provable security, BAN logical analysis, and Scyther formal analysis. Additionally, the performance of the improved protocol was compared with other similar protocols. The results show that the new protocol is not only secure and feasible, but also has high computational efficiency and communication efficiency, which meets the working requirements of clustered wireless network environment.
表 1 BAN逻辑符号定义Table 1 Definitions of BAN logic symbols |
| 符号 | 含义 |
| 主体 | |
| 语句 | |
| 密钥 | |
| 会话密钥 | |
| 主体 | |
| 与 | |
表 3 基础运算耗时(ms)Table 3 Time consuming of basic operations (ms) |
| 运算 | ||||||
| 平均值 | 8.231 3 | 0.923 7 | 25.132 8 | 8.587 6 | 0.074 4 | 0.021 4 |
表 4 计算开销对比Table 4 Comparison of computation overhead |
| 协议 | 计算开销/ms | 总耗时/ms | 交互次数 |
| 文献[17] | 117.214 | 3 | |
| 文献[18] | 4 | ||
| IBAKAS | 3 | ||
| eIBAKAS | 2 |
| 1 |
MUGHAL F R, HE J, ZHU N, et al. Resource management in multi-heterogeneous cluster networks using intelligent intra-clustered federated learning[J]. Computer Communications, 2024, 213, 236- 245.
|
| 2 |
DIFFIE W, HELLMAN M. New directions in cryptography[J]. IEEE Transactions on Information Theory, 1976, 22 (6): 644- 654.
|
| 3 |
RIVEST R, SHAMIR A, ADLEMAN L. A method for obtaining digital signatures and public key cryptosystems[J]. Communications of the ACM, 1978, 21 (2): 120- 126.
|
| 4 |
SHAMIR A. Identity based cryptosystems and signature schemes[C]//Workshop on the Theory and Application of Cryptographic Techniques. Berlin,Heidelberg:Springer,1984:47-53.
|
| 5 |
AL-RIYAMI S S,PARTERSON K G. Certificateless public key cryptography[C]//International Conference on the Theory and Application of Cryptology and Information Security. Berlin,Heidelberg:Springer,2003:452-473.
|
| 6 |
LIU Z,DAI L,YUAN Y,et al. Distributed joint optimal control of power and rate with clustered routing protocol in wireless sensor networks[C]//Advances in Wireless Sensor Networks. Berlin,Heidelberg:Springer,2012:325-334.
|
| 7 |
PAZZI R W, BOUKERCHE A, LYNDA M, et al. A clustered trail-based data dissemination protocol for improving the lifetime of duty cycle enabled wireless sensor networks[J]. Wireless Networks, 2017, 23 (1): 177- 192.
|
| 8 |
JADIDOLESLAMY H. A hierarchical multipath routing protocol in clustered wireless sensor networks[J]. Wireless Personal Communications, 2017, 96, 4217- 4236.
|
| 9 |
BABIKER A E, ELMALEEH M, ABBAS O, et al. Data-based energy efficient clustered routing protocol for wireless sensors networks-tabuk flood monitoring system case study[J]. International Journal of Recent Contributions from Engineering Science, 2017, 5 (3): 58- 70.
|
| 10 |
AMJAD M, AFZAL M K, UMER T, et al. QoS-aware and heterogeneously clustered routing protocol for wireless sensor networks[J]. IEEE Access, 2017, 5, 10250- 10262.
|
| 11 |
SINGH P, SINGH R. Energy-efficient QoS-aware intelligent hybrid clustered routing protocol for wireless sensor networks[J]. Journal of Sensors, 2019, 1- 12.
|
| 12 |
ADNAN M, YANG L, TAZEEM A, et al. An unequally clustered multi-hop routing protocol based on fuzzy logic for wireless sensor networks[J]. IEEE Access, 2021, 9, 38531- 38545.
|
| 13 |
MEZRAG F, BITAM S, ABDELHAMID M. An efficient and lightweight identity-based scheme for secure communication in clustered wireless sensor networks[J]. Journal of Network and Computer Applications, 2022, 200, 282- 331.
|
| 14 |
KIRUBA G, JOSELIN B. TSO clustered protocol to extend lifetime of IoT based mobile wireless sensor networks[J]. The International Arab Journal of Information Technology, 2023, 20 (4): 559- 566.
|
| 15 |
KIM Y, LIM E, KWON T. On the impact of deployment errors in location-based key predistribution protocols for wireless sensor networks[J]. IEEE Access, 2024, 12, 35765- 35778.
|
| 16 |
LAMACCHI B,LAUTER K,MITYAGINA A. Stronger security of authenticated key exchange[C]//Provable Security. Berlin,Heidelberg:Springer,2007:1-16.
|
| 17 |
宋庆, 马米米, 邓淼磊, 等. 轻量级的两方认证密钥协商协议[J]. 计算机工程与应用, 2024, 60 (14): 283- 293.
SONG Q, MA M M, DENG M L, et al. Lightweight two-party authentication key agreement protocol[J]. Computer Engineering and Applications, 2024, 60 (14): 283- 293.
|
| 18 |
贺嘉琦, 彭长根, 付章杰, 等. 面向RFID的轻量级双向认证协议[J]. 计算机工程与应用, 2023, 59 (18): 268- 277.
HE J Q, PENG C G, FU Z J, et al. Lightweight bidirectional authentication protocol for RFID[J]. Computer Engineering and Applications, 2023, 59 (18): 268- 277.
|
| 19 |
BURROWS M, ABADI M, NEEDHAM R. A logic of authentication[J]. ACM Transactions on Computer Systems, 1989, 23 (5): 1- 13.
|
/
| 〈 |
|
〉 |