针对移动自组网群通信中的安全问题,提出1种多层移动自组网安全分层密钥管理方案(HKMS)。其具体内容是:首先,为了简化群结构的管理,基于多层结构模型提出双层密钥管理方案,采用节点间的交换密钥和群密钥对数据包进行双重加密,提高网络通信的安全性;针对移动自组网拓扑结构频繁变化导致群结构维护复杂问题,对节点加入和节点离开2方面进行讨论;其次,从前向安全和后向安全2方面对方案的安全性进行分析;最后,与类似方案的性能进行比较分析。研究结果表明:该方案对节点的存储量要求较低,节点加入退出相关操作的执行效率等较高,简化了群管理与维护,能有效地减少群密钥重分发数。
In order to insure the security of communication in MANETs (Mobile ad hoc networks), a secure hierarchical key management scheme (HKMS) in MANETs was proposed. The real procedures were as follows. Firstly, in order to make the management of group structure much easier, a two-layer key management scheme was introduced using the multi-layer structure model. This scheme suggests encrypting a packet twice with session keys between nodes and group keys respectively to improve the security of communication in MANETs. Secondly, due to the frequent changes of the network’s topology, it is complex to maintain a group structure, the group maintenance on the view of a node’s join and leave was discussed. Then the scheme’s security on forward and backward security were analyzed, The results show that HKMS has lower requirement of node storage ability and higher implementation efficiency when nodes join or leave the MANNETs, and it also simplifies the group management and maintenance and reduces the key redistribution cost.