CONSTRAINTS AND APPROACHES FOR DISTRIBUTED SENSOR NETWORK SECURITY

CONSTRAINTS AND APPROACHES FOR DISTRIBUTED SENSOR NETWORK SECURITY
复制标题

DOI:
--
复制
发表时间:
2000
期刊:
Acta Geologica Sinica ‐ English Edition
影响因子:
--
通讯作者:
D. Carman;P. Kruus;B. Matt
D. Carman;P. Kruus;B. Matt
中科院分区:
其他
文献类型:
--
作者:
D. Carman;P. Kruus;B. Matt

文献摘要

被引文献

相似文献

执行摘要 机密性、完整性和身份验证服务对于防止对手损害分布式传感器网络的安全至关重要。密钥管理对于建立提供这种保护所需的密钥同样至关重要。然而,由于传感器网络环境的临时性质、间歇性连接和资源限制,提供密钥管理很困难。作为 SensIT 计划的一部分,NAI 实验室正在通过识别和开发有效提供密钥管理安全支持服务的加密协议和机制来解决这一问题。本文件描述了我们 2000 财年的传感器网络限制和关键管理方法研究。作为第一步,NAI 实验室研究了战场传感器和传感器网络技术以及将部署该技术的独特通信环境。我们已经确定了针对机密性和组级身份验证提供密钥管理问题的特定要求。我们还发现了一些制约因素,特别是能源消耗,使得这个问题变得困难。 NAI Labs 开发了专为分布式传感器网络环境设计的新型密钥管理协议,包括基于身份的对称密钥和 Rich Uncle。我们分析了现有的和 NAI 实验室开发的键控协议,以确定它们在满足既定要求的同时克服战场能量限制的适用性。我们的研究主要集中在密钥管理能耗、基于整个系统、平均传感器节点和单个传感器节点能耗的协议评估。我们检查了许多基于密钥的协议,确定了一些协议适合传感器网络,但所有协议都具有灵活性限制。基于密钥的协议通常是节能的,使用消耗相对较少能量的加密和散列算法。基于秘密密钥的协议的安全性通常由所建立的密钥的粒度来确定,对于本文描述的协议,其变化很大。在我们检查这些协议的过程中,我们注意到其中一些协议对于战场传感器网络的使用不够灵活,因为它们无法有效地处理网络中意外添加的传感器节点。我们的基于身份的对称密钥协议和效率较低的基于对称密钥证书的协议非常适合某些传感器网络,建立粒度密钥,同时消耗相对较少的能量。然而,所有基于安全密钥的协议都使用作为密钥分发中心(或转换器)运行的特殊节点。作为密钥建立过程的一部分,传感器节点与这些中心交换信息进行通信。由于这些特殊节点预计将占传感器的不到 1%……
Executive Summary Confidentiality, integrity, and authentication services are critical to preventing an adversary from compromising the security of a distributed sensor network. Key management is likewise critical to establishing the keys necessary to provide this protection. However, providing key management is difficult due to the ad hoc nature, intermittent connectivity, and resource limitations of the sensor network environment. As part of the SensIT program, NAI Labs is addressing this problem by identifying and developing cryptographic protocols and mechanisms that efficiently provide key management security support services. This document describes our sensor network constraints and key management approaches research for FY 2000. As a first step, NAI Labs has researched battlefield sensor and sensor network technology and the unique communications environment in which it will be deployed. We have identified the requirements specific to our problem of providing key management for confidentiality and group-level authentication. We have also identified constraints, particularly energy consumption, that render this problem difficult. NAI Labs has developed novel key management protocols specifically designed for the distributed sensor network environment, including Identity-Based Symmetric Keying and Rich Uncle. We have analyzed both existing and NAI Labs-developed keying protocols for their suitability at satisfying identified requirements while overcoming battlefield energy constraints. Our research has focused heavily on key management energy consumption, evaluating protocols based on total system, average sensor node, and individual sensor node energy consumption. We examined a number of secret-key-based protocols, determining some to be suitable for sensor networks but all of the protocols have flexibility limitations. Secret-key-based protocols are generally energy-efficient, using encryption and hashing algorithms that consume relatively little energy. Security of secret-key-based protocols is generally determined by the granularity of established keys, which vary widely for the protocols described herein. During our examination of these protocols we noted that some of these protocols are not sufficiently flexible for use in battlefield sensor network, since they cannot efficiently handle unanticipated additions of sensor nodes to the network. Our Identity-Based Symmetric Keying protocol and the less efficient Symmetric Key Certificate Based Protocol are well suited for certain sensor networks, establishing granular keys while consuming relatively little energy. However, all of the secure secret-key-based protocols use special nodes that operate as Key Distribution Centers (or Translators). The sensor nodes communicate with these centers exchanging information as part of the key establishment process. Since these special nodes are expected to make up less than 1% of the sensor …