XAuth: Secure and Privacy-Preserving Cross-Domain Handover Authentication for 5G HetNets

XAuth: Secure and Privacy-Preserving Cross-Domain Handover Authentication for 5G HetNets
复制标题

DOI:
10.1109/jiot.2022.3223223
复制
发表时间:
2023-04
影响因子:
10.6
通讯作者:
Mingjun Wang;Dongsheng Zhao;Zheng Yan;Haiguang Wang;Tieyan Li
Mingjun Wang;Dongsheng Zhao;Zheng Yan;Haiguang Wang;Tieyan Li
中科院分区:
计算机科学1区
文献类型:
--
作者:
Mingjun Wang;Dongsheng Zhao;Zheng Yan;Haiguang Wang;Tieyan Li

文献摘要

相似文献

由于毫米波的低渗透率和不同接入技术的可用性,第五代(5G)网络具有高度异构性,具有超高密度基站(BSS)。然而,5G网络的不断异构化和致密化对网络安全提出了巨大挑战,尤其是对用户移动性的支持。在BSS之间或不同网域之间的用户切换过程中,与4G网络相比,用户接入认证和安全会话建立的风险要高得多。一方面,在超密集网络中,随着切换变得更加频繁,切换认证的开销显著增加。另一方面,异质网络(HetNets)中安全方案的差异化对切换认证提出了很大的挑战。成功设计一个安全、隐私保护、高效的适用于异质超密集5G网络的切换认证协议,将极大地拓展未来5G网络应用的前景。虽然已经提出了许多解决方案(例如基于挑战-响应的方案、基于公钥密码的方案、基于物理层信息的方案和基于区块链的方案)来解决跨域切换认证问题,但大多数方案都避免了安全和隐私漏洞以及不合理的性能开销。在本文中,我们提出了一种基于区块链的5G HetNet域内和域间切换的安全和隐私保护认证协议XAuth。该协议能够实现用户设备(UE)与目标网络之间的双向认证和密钥协商,具有前向保密性、后向保密性、用户匿名性和有条件隐私保护等特点。形式化的安全性分析和综合性能评估证明了该协议的安全性和有效性。
Fifth generation (5G) networks are highly heterogeneous, with ultradense base stations (BSs), due to the low penetration of millimeter waves and the availability of different access technologies. However, the continuous heterogeneity and densification of 5G networks pose great challenges to network security, especially for user mobility support. In the process of user handover between BSs or between different network domains, user access authentication and security session establishment are far riskier compared to 4G networks. On the one hand, the overhead of handover authentication increases significantly as handovers become more frequent in an ultradense network. On the other hand, the differentiation of security schemes in heterogeneous networks (HetNets) poses a big challenge to handover authentication. Successfully designing a secure, privacy preserving, and efficient handover authentication protocol for heterogeneous and ultradense 5G networks would substantially expand the prospects of future 5G network applications. Although numerous solutions (e.g., challenge-response-based, public key cryptography-based, physical-layer information-based, and blockchain-based solutions) have been proposed to solve the cross-domain handover authentication problem, most of them surfer from security and privacy vulnerabilities and unreasonable performance overhead. In this article, we propose XAuth, a secure and privacy-preserving authentication protocol for both intradomain and interdomain handover in 5G HetNets based on blockchain. The proposed protocol can achieve mutual authentication, key agreement between user equipment (UE) and target network, and is characterized by forward secrecy, backward secrecy, user anonymity, and conditional privacy preservation. Formal security analysis and comprehensive performance evaluation demonstrate the security and effectiveness of the proposed protocol.