分析传统的匿名漫游认证协议,指出其匿名不可控和通信时延较大的不足.针对上述不足,提出异构无线网络可控匿名漫游认证协议,远程网络认证服务器通过1轮消息交互即可完成对移动终端的身份合法性验证,当移动终端发生恶意操作时,家乡网络认证服务器可协助远程网络认证服务器撤销移动终端的身份匿名性.该协议在实现匿名认证的同时,还具有恶意匿名的可控性,有效防止了恶意行为的发生,且其通信时延较小.安全性证明表明,该协议在CK安全模型中是可证安全的.相对于传统漫游机制而言,该协议更适合于异构无线网络.
This paper analyzes the traditional anonymous roaming authentication protocol, and points out the deficiencies of their uncontrolled anonymity and communication delay. A controllable anonymous roaming authentication protocol is proposed in this paper for heterogeneous wireless networks. This protocol can complete verifying the legitimacy of the identity of the mobile terminal through one .message interaction. If the mobile terminal has malicious operation, the home network authentication server can help remote network authentication server to revoke the identity anonymity of the mobile terminal. The protocol accomplishes anonymous authentication and possesses controllability on malicious anonymity at the same time, thus effectively preventing the occurrence of malicious behavior and the communication delay. This protocol is safe in the CK security model.