家庭基站是一种室内小型蜂窝基站,由于其设备部署在不可信的环境中,因此接入运营商的核心网时必须进行认证。3GPP组织已提出了使用IKEv2承栽EAP-AKA/SIM的家庭基站设备的初始认证方法,该文基于3GPP标准提出一种家庭基站设备的快速重认证方法,在不降低原有安全级别的前提下,对初始认证进行优化,减少了通信开销,加快了认证的速度。对标准中的设施不做任何修改的情况下,使其在实际应用中便于实施。使用AvIsPA对方案的安全性进行了分析,并在能量消耗和通信开销方面与初始认证进行了详细的比较,结果表明本方案性能良好。
Home eNodeB (HeNB) is a small cellular base station, typically designed for use in a home or small business. Deployed in untrusted environments, HeNB must be authenticated when it accesses to operator's core network. 3GPP has presented a method that EAP-AKA runs within IKEv2 between HeNB and security gateway for mutual authentication of HeNB and core network. This paper proposes a fast re-authentication scheme based on 3GPP standard. The proposed procedures reduce significantly the authentication overhand and improve the authentication speed compared with the initial authentication, without compromising the provided security services. Moreover, the proposed method does not modify the infrastructure in 3GPP and can be applied easily to the HeNB system. A detailed analysis of security is made by using AVISPA. In addition, an analysis of energy cost is carried out that compares the energy consumption induced by re-authentication and initial authentication. Finally, an analysis of communication cost analysis is provided that estimates the cost improvement of proposed re-authenitication over the initial authentication procedure.