访问控制是传感器网络中极具挑战性的安全问题之一.传感器网络作为服务提供者向合法用户提供环境监测数据请求服务.现有的基于公钥的传感器网络访问控制方式开销较大,难以抵制节点捕获、DoS和信息重放等攻击.为此,提出了基于单向Hash链的访问控制方式.为了增加用户数量、访问能力的可扩展性以及抵制用户捕获攻击,提出了基于Merkle哈希树的访问控制方式和用户访问能力撤销方式.分析、评估和比较的结果显示与现有的传感器网络访问控制方式相比,该方式的计算、存储和通信开销较小,能够抵制节点捕获、请求信息重放和DoS攻击.
Access control is one of the most challenging security problems in sensor networks. Sensor networks provide the query service of the environmental monitoring data as the service provider to the users. The current access control scheme based on public key cryptography is high in expense, and resists node capture, query replay and DoS attacks with difficulty. This paper proposes one-way hash chain based access control schemes. To increase the scalability of users and access capability, and to resist users being compromised, several effective access control schemes based on the Merkle hash tree and revoking user access control capability are proposed. Analysis, evaluation and comparison show that these schemes have several advantages over the current access control methods of low expense in calculation, storage and communication, and resistance to node capture, query replay and DoS attacks.