检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:孙中岫 彭诚 范伟[1,2] SUN Zhongxiu;PENG Cheng;FAN Wei(Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China;School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100049,China)
机构地区:[1]中国科学院信息工程研究所,北京100093 [2]中国科学院大学网络空间安全学院,北京100049
出 处:《信息网络安全》2024年第8期1220-1230,共11页Netinfo Security
基 金:国家重点研发计划[2021YFB2700603]。
摘 要:5G技术的普及促进了各行业生产力的发展,但5G网络的安全性问题也逐渐凸显,基站作为连接用户设备和核心网的枢纽,其安全性备受关注。由于基站通过广播发送的系统消息缺乏真实性和完整性的保护,攻击者可以通过修改系统消息,吸引用户设备在初始接入或者在小区重选时连接到伪基站,从而发起多种后续攻击。针对这一问题,文章提出了一种基于无证书签名的基站身份认证协议,为用户设备提供了一种验证基站广播系统消息合法性的方法,并从签名消息的选择、签名和验证的开销、抵御重放攻击几个方面进行了优化。仿真实验表明,该协议引入的计算开销是基站和用户设备可以接受的,与现有的基站身份认证协议相比,该协议提高了安全性,实现了更小的签名长度。The popularization of 5G technology has promoted the development of productivity in various industries,but the security of 5G networks has gradually become prominent,and the security of base stations,as a hub connecting user equipment and the core network,has attracted much attention.Due to the lack of authenticity and integrity protection of the system information messages sent by the base station through broadcasting,attackers can modify the system information messages to attract user devices to connect to the fake base station during initial access or cell reselection,so as to launch a variety of subsequent attacks.In order to solve this problem,this paper proposed a base station identity authentication protocol based on certificateless signature,which provided a method for user equipment to verify the legitimacy of base station broadcasting system messages,and optimized the selection of signed messages,the overhead of signing and verification,and the defense against replay attacks.Simulation results show that the computational overhead introduced by this scheme is acceptable to the base station and user equipment,and compared with the existing base station identity authentication protocols,the proposed scheme improves the security and achieves the minimum signature length.
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:18.188.39.45