针对WLAN Mesh网络中Mesh接入点(MAP)移动时快速切换认证过程中存在的安全问题,采用基于邻居图的快速切换方法和基于矩阵的密钥预分配方法,提出一种快速切换认证方案,该方案能够适应具有移动MAP的WLAN Mesh网络场景.利用Canetti-Krawczyk模型对提出的认证方案进行安全性分析,并对方案中所需的计算和存储代价进行估计.结果表明,在伪随机函数和消息认证码函数是安全的前提下,方案中的认证协议在UM中是SK-安全的,且该方案具有较小的计算和存储代价.
The security problem of fast handoffs in WLAN mesh networks with mobile mesh access point (MAP) was analyzed. Based on the neighbor graph fast handover method and matrix-based key pre-distribution scheme, an authentication scheme for fast handoff was proposed. The scheme is suitable to the WLAN mesh networks with mobile MAP. Based on Canetti - Krawczyk model, the improved d - way handshake protocol in the scheme was analyzed. And computation overhead and memory cost were evaluated. The results show that it is SK - secure in UM if the pseudorandom function and MAC function in use are secure against chosen message attacks. The performance shows that the proposed scheme has less computation overhead and memory cost.