FSASD: A framework for establishing security associations for sequentially deployed WMN

FSASD: A framework for establishing security associations for sequentially deployed WMN
复制标题

FSSD:为顺序部署的 WMN 建立安全关联的框架

DOI:
10.1109/wowmom.2012.6263782
复制
发表时间:
2012
期刊:
2012 IEEE International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM)
影响因子:
--
通讯作者:
Ulrike Meyer
Ulrike Meyer
中科院分区:
--
文献类型:
--
作者:
André Egners;Hendrik Fabelje;Ulrike Meyer

文献摘要

被引文献

相似文献

无线网状网络(WMN)主要由无线互连的网状路由器(MR)的基础设施组成。在许多应用场景中,这些MR被放置在可公开访问的位置,因此可能被攻击者破坏。因此,WMN的任何安全框架都应该能够科普受损的网状路由器。此外,网格客户端(MC)通常被假设为能够为彼此路由业务。这样的路由MC以及受损的MR可以尝试窃听和操纵流过它们的任何类型的业务。因此,必须确保网状网中所有通信的端到端保护。无论是即将到来的802.11标准,还是先前的安全框架研究提案,都无法充分应对这一挑战。此外,许多研究提案与即将推出的标准不兼容,因此只有很小的机会与市售设备一起广泛使用。在本文中,我们提出了一个全面的框架,以确保无线网状网络,是完全兼容即将到来的802.11s。该框架能够有效地建立网状网中不同流量类型的端到端保护所需的所有安全关联。此外,该框架还支持安全的主动转发器。我们实现了整个框架在我们的WMN测试床,并在本文中提出的性能结果。
Wireless Mesh Networks (WMN) mainly consist of an infrastructure of mesh routers (MRs) that are wirelessly interconnected. In many application scenarios these MRs are placed in publicly accessible places and may therefore be compromised by an attacker. Any security framework for WMNs should thus be able to cope with compromised mesh routers. In addition, mesh clients (MCs) are often assumed to be able to route traffic for each other. Such routing MCs, as well as compromised MRs, may try to eavesdrop on and manipulate any type of traffic flowing through them. As a consequence end-to-end protection of all communication in the mesh has to be ensured. Neither the upcoming standard 802.11s nor prior research proposals of security frameworks adequately address this challenge. In addition, many research proposals are incompatible to the upcoming standard therefore only have a slight chance of getting widely used with commercially available devices. In this paper we propose a comprehensive framework for securing wireless mesh networks that is fully compatible to the upcoming 802.11s. The framework enables the efficient establishment of all security associations required for end-to-end protection of the different traffic types in the mesh. In addition, the framework supports secure proactive handovers. We implemented the entire framework in our WMN testbed and present the performance results in this paper.