DocumentCode
2770562
Title
A Novel Compromise-Resilient Authentication System for Wireless Mesh Networks
Author
Lin, Xiaodong ; Lu, Rongxing ; Ho, Pin-Han ; Shen, Xuemin Sherman ; Cao, Zhenfu
Author_Institution
Dept. of Electr. & Comput. Eng., Waterloo Univ., Ont.
fYear
2007
fDate
11-15 March 2007
Firstpage
3541
Lastpage
3546
Abstract
User authentication is essential in service-oriented communication networks to identify and reject any unauthorized network access. The state-of-the-art practice in securing wireless networks is based on the technique of authentication, authorization and accounting (AAA) framework where an AAA server is adopted to authenticate mobile users (MUs), handle authorization requests, and collect accounting data. However, the traditional AAA framework is by way of a single authentication server, and cannot tolerate AAA server failure due to various malicious attacks such as denial-of-service (DoS) attack, or any other failure event such that the authentication server is compromised due to misuse, misconfiguration and malicious access, etc. Thus, a more resilient approach is to adopt multiple authentication servers, where any authentication request is handled by more than one authentication servers in order to resist any compromise event of an authentication server. To meet this design objective, we introduce a novel compromise-resilient authentication system based on (t, n) threshold signature technique. With the proposed system, only t or more out of n authentication servers can cooperatively allow a MU to have network access, and any t-1 or less cannot. Case study of reliability analysis is conducted to demonstrate the effectiveness of the system. The proposed authentication system is expected to particularly contribute to wireless mesh networking (WMN) in metropolitan areas where thousands of nodes may coexist and are managed under a single control plane such that duplicated AAA servers are necessary.
Keywords
message authentication; telecommunication security; wireless LAN; authentication, authorization and accounting server; compromise-resilient authentication system; multiple authentication servers; single authentication server; threshold signature technique; user authentication; wireless mesh networks; Authentication; Authorization; Communication networks; Communication system security; Computer crime; Hardware; Network servers; Wireless LAN; Wireless mesh networks; Wireless networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Wireless Communications and Networking Conference, 2007.WCNC 2007. IEEE
Conference_Location
Kowloon
ISSN
1525-3511
Print_ISBN
1-4244-0658-7
Electronic_ISBN
1525-3511
Type
conf
DOI
10.1109/WCNC.2007.649
Filename
4224894
Link To Document