{"title":"基于mec的5G网络中一种新的面向组的切换认证方案","authors":"Chengzhe Lai, Yixiao Ma","doi":"10.1109/iccc52777.2021.9580296","DOIUrl":null,"url":null,"abstract":"With the rapid development of 5G, ultra-dense base station deployment will result in frequent handovers during user movement, increasing authentication delay. Moreover, a large number of users competing for a limited number of wireless channels will increase the probability of signaling collisions and cause network congestion. In this paper, based on the 5G network integrated by mobile edge computing (MEC) and software defined network (SDN), we propose an anonymous handover authentication scheme which supports multi-user access. Particularly, it provides lightweight user grouping and internal group authentication. In addition, by utilizing the aggregation message authentication code with detection function (AMAD) technique, multiple users can be authenticated simultaneously to reduce the number of signaling, and the identity list corresponding to the malicious MAC can be accurately identified and output, which can effectively resist to DoS attack. The security analysis proves that the scheme can provide robust security protection, and it is suitable for intra-domain handover and inter-domain handover. Compared with the existing group-based handover authentication schemes, the proposed scheme has moderate computational and communication overhead while its functions are superior to other schemes.","PeriodicalId":425118,"journal":{"name":"2021 IEEE/CIC International Conference on Communications in China (ICCC)","volume":"85 4","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-07-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"A Novel Group-oriented Handover Authentication Scheme in MEC-Enabled 5G Networks\",\"authors\":\"Chengzhe Lai, Yixiao Ma\",\"doi\":\"10.1109/iccc52777.2021.9580296\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"With the rapid development of 5G, ultra-dense base station deployment will result in frequent handovers during user movement, increasing authentication delay. Moreover, a large number of users competing for a limited number of wireless channels will increase the probability of signaling collisions and cause network congestion. In this paper, based on the 5G network integrated by mobile edge computing (MEC) and software defined network (SDN), we propose an anonymous handover authentication scheme which supports multi-user access. Particularly, it provides lightweight user grouping and internal group authentication. In addition, by utilizing the aggregation message authentication code with detection function (AMAD) technique, multiple users can be authenticated simultaneously to reduce the number of signaling, and the identity list corresponding to the malicious MAC can be accurately identified and output, which can effectively resist to DoS attack. The security analysis proves that the scheme can provide robust security protection, and it is suitable for intra-domain handover and inter-domain handover. Compared with the existing group-based handover authentication schemes, the proposed scheme has moderate computational and communication overhead while its functions are superior to other schemes.\",\"PeriodicalId\":425118,\"journal\":{\"name\":\"2021 IEEE/CIC International Conference on Communications in China (ICCC)\",\"volume\":\"85 4\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-07-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE/CIC International Conference on Communications in China (ICCC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/iccc52777.2021.9580296\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE/CIC International Conference on Communications in China (ICCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/iccc52777.2021.9580296","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
摘要
随着5G的快速发展,超密集的基站部署将导致用户移动过程中频繁切换,增加认证延迟。此外,大量用户竞争有限的无线信道会增加信令冲突的概率,造成网络拥塞。本文基于移动边缘计算(MEC)和软件定义网络(SDN)融合的5G网络,提出了一种支持多用户接入的匿名切换认证方案。特别是,它提供了轻量级的用户分组和内部组身份验证。此外,利用AMAD (aggregation message authentication code with detection function)技术,可以同时对多个用户进行认证,减少信令数量,准确识别并输出恶意MAC对应的身份列表,可以有效抵御DoS攻击。安全性分析表明,该方案能够提供鲁棒性的安全保护,适用于域内切换和域间切换。与现有的基于组的切换认证方案相比,该方案计算量和通信开销适中,功能优于其他方案。
A Novel Group-oriented Handover Authentication Scheme in MEC-Enabled 5G Networks
With the rapid development of 5G, ultra-dense base station deployment will result in frequent handovers during user movement, increasing authentication delay. Moreover, a large number of users competing for a limited number of wireless channels will increase the probability of signaling collisions and cause network congestion. In this paper, based on the 5G network integrated by mobile edge computing (MEC) and software defined network (SDN), we propose an anonymous handover authentication scheme which supports multi-user access. Particularly, it provides lightweight user grouping and internal group authentication. In addition, by utilizing the aggregation message authentication code with detection function (AMAD) technique, multiple users can be authenticated simultaneously to reduce the number of signaling, and the identity list corresponding to the malicious MAC can be accurately identified and output, which can effectively resist to DoS attack. The security analysis proves that the scheme can provide robust security protection, and it is suitable for intra-domain handover and inter-domain handover. Compared with the existing group-based handover authentication schemes, the proposed scheme has moderate computational and communication overhead while its functions are superior to other schemes.