Fast Hierarchical Key Management Scheme With Transitory Master Key for Wireless Sensor Networks

Fast Hierarchical Key Management Scheme With Transitory Master Key for Wireless Sensor Networks
复制标题

DOI:
10.1109/jiot.2016.2599641
复制
发表时间:
2016-08
影响因子:
10.6
通讯作者:
F. Gandino;R. Ferrero;B. Montrucchio;M. Rebaudengo
F. Gandino;R. Ferrero;B. Montrucchio;M. Rebaudengo
中科院分区:
计算机科学1区
文献类型:
--
作者:
F. Gandino;R. Ferrero;B. Montrucchio;M. Rebaudengo

文献摘要

被引文献

相似文献

对称加密是无线传感器网络中最广泛采用的安全解决方案。在这种情况下,主要的开放问题是由对称密钥的建立。尽管已经提出了许多密钥管理方案以保证高安全级别,但是还不存在没有弱点的解决方案。一类重要的密钥管理方案是基于临时主密钥(MK)的。在这种方法中,在初始化阶段使用全局秘密来生成成对密钥,并在工作阶段删除全局秘密。然而,如果攻击者在删除MK之前危害节点,则整个网络的安全性会受到损害。本文提出了一种新的密钥协商方案。新的例程集成了一个众所周知的密钥计算机制的基础上,一个短暂的主秘密。所提出的方法的目标是减少初始化阶段所需的时间,从而降低主秘密被泄露的概率。这一目标是通过将初始化阶段划分为具有更高安全级别的分层子阶段来实现的。实验分析表明,该方案提供了一个显着减少删除临时秘密材料之前所需的时间,从而提高了整体的安全水平。此外,所提出的方案允许在第一次部署后添加新的节点,并具有能够在与初始部署相同的时间内完成密钥建立的合适例程。
Symmetric encryption is the most widely adopted security solution for wireless sensor networks. The main open issue in this context is represented by the establishment of symmetric keys. Although many key management schemes have been proposed in order to guarantee a high security level, a solution without weaknesses does not yet exist. An important class of key management schemes is based on a transitory master key (MK). In this approach, a global secret is used during the initialization phase to generate pair-wise keys, and it is deleted during the working phase. However, if an adversary compromises a node before the deletion of the MK, the security of the whole network is compromised. In this paper, a new key negotiation routine is proposed. The new routine is integrated with a well-known key computation mechanism based on a transitory master secret. The goal of the proposed approach is to reduce the time required for the initialization phase, thus reducing the probability that the master secret is compromised. This goal is achieved by splitting the initialization phase in hierarchical subphases with an increasing level of security. An experimental analysis demonstrates that the proposed scheme provides a significant reduction in the time required before deleting the transitory secret material, thus increasing the overall security level. Moreover, the proposed scheme allows to add new nodes after the first deployment with a suited routine able to complete the key establishment in the same time as for the initial deployment.