无线传感器网络具有拓扑易变化、节点能源受限、网络易受攻击等特性,这些特性决定了无线传感器网络需要特殊的安全保障机制,尤其要解决其涉及到的机密性、完整性、端点认证及在有限的空间存储大量的密钥等问题。当前的研究工作不能有效地解决无限传感器节点容量受限与节点需要大量存储共享密钥之间的矛盾,导致大量传感器节点因与相邻节点没有共享密钥而无法安全交换信息。针对这一问题提出一种基于组合密钥(combined key,CK)的密钥管理技术。该方案采用种子密钥映射技术,以较少密钥因子组合大量相异的密钥,解决传感器节点密钥存储空间受限问题,保障任何相邻节点之间都能共享密钥。并能实现可认证的密钥共享机制,弥补了传感器网络没有认证中心的缺陷。经分析,该方案在安全性、存储性和节能方面有较好的优势。
Wireless sensor networks have such obvious characteristics as energy-constraint and dynamic topology. Therefore,key management mechanism in wireless sensor networks needs to solve confidentiality,integrity and endpoint authentication and the problem of storing a lot of key information in limited space. The current studies can not solve these issues that a large number of key could not be stored because of limited storage space in sensor nodes and a large number of sensor nodes could not exchange their information because they have no shared key information with their adjacent nodes. Aimed at these limitations aforementioned,a combined key( CK) management scheme in wireless sensor networks is proposed in this paper,which adopts the seed key mapping technology that combines a few key factors into a large number of difference keys in order to solve limited storage space in sensor nodes and uses elliptic curve public key cryptography and designs a public key corresponding to the same two private keys that are encryption key and decryption key respectivelyused in communication between two sensor nodes and in mutual authentication in order to share key information between adjacent nodes and to make up for deficiencies of no certification center in sensor networks. Performance analysis proves that the CK management scheme has advantages in security,storage performance,and energy consumption.