119 | 2 | 30 |
下载次数 | 被引频次 | 阅读次数 |
LTE用户切换时的密钥管理在很大程度上关系着用户安全,切换密钥管理包括密钥的生成、分发、更新和撤销。对现有长期演进(Long Term Evolution,LTE)网络切换密钥管理更新机制进行简要介绍,包括X2和S1切换密钥更新方案。针对X1切换仅有两跳前向密钥隔离的安全缺陷,借鉴S1切换方案设计思想,提出一跳前向密钥隔离的X2切换密钥更新方案(OFKS-X2),并对OFKS-X2密钥更新方案进行了安全性和实用性分析。结果表明,OFKS-X2密钥更新方案能够提供一跳前向密钥隔离,对协议有效性影响不大,且用户的消息工作量没有变化,网络侧的消息处理复杂度略有增加,用户侧计算量基本不变,网络侧计算量略有增加。
Abstract:Key management has a big impact on LTE user security in handover process. Handover key management includes handover key generation,distribution,refresh and revocation. In this paper,we will introduce the handover key refresh mechanism in detail,including X2 handover key refresh scheme and S1 handover key refresh scheme. Finally,with reference to the S1 handover scheme,an enhanced X2 handover key refresh scheme OFKS( One-hop Forward Key Separation) X2 handover key refresh scheme is put forward to over come the disadvantage of the original one in LTE which can only provide two-jump forward security by advancing the time when MME is involved in the agreement.Analysis results show that the OFKS-X2 key update scheme can provide a jump forward to the key and has little effect on the protocol. No changes happen in the user's message workload and side calculation. However the complexity of message processing and calculation in the network side is slightly increased.
[1]沈嘉,索士强,全海洋,等.3GPP长期演进(LTE)技术原理与系统设计[M].北京:人民邮电出版社,2008.
[2]SESIA S,TOUFIK I,BAKER M.LTE:The UMTS Long Term Evolution[M].New York:John Wiley&Sons,2009.
[3]杜金宇,程锋,蒋群,等.LTE全球主流运营商及产业链发展动态[J].电信工程技术与标准化,2012,25(7):17-22.
[4]李进良.加速TD-LTE全国4G网建设共同促进全民信息消费[J].移动通信,2014,38(1):17-20.
[5]曾勇.LTE/SAE密钥管理技术研究[J].通信技术,2009(7):97-100.
[6]胡国华,袁树杰,谭敏.4G移动通信技术与安全缺陷分析[J].通信技术,2008,41(7):155-157.
[7]李泰成,何莉,吴槟.具有一跳前向安全性的X2切换密钥更新协议[J].计算机系统应用,2011,20(8):67-71.
[8]赵伦.LTE系统中的S1切换技术研究与设计[D].武汉:武汉邮电科学研究院,2012.
[9]3GPP TS33.401 V9.0.0(2009-06).Security Architecture(Release 9)[S],2009.
[10]许盛宏,李力卡,陈庆年.LTE网络MME的安全容灾方案研究[J].移动通信,2015,39(22):9-13.
[11]楚佩佳.基于LTE系统的UE随机接入过程研究[D].杭州:杭州电子科技大学,2011.
[12]FORSBERG D,HORN G,MOELLER W D,et al.LTE Security[M].New York:John Wiley&Sons,2012.
[13]汪良辰.LTE安全接入机制研究[D].西安:西安电子科技大学,2012.
[14]高枫,李一喆,马铮,等.LTE网络安全部署研究[J].移动通信,2014,38(23):25-28.
基本信息:
DOI:
中图分类号:TN929.5
引用信息:
[1]朱诗兵,周赤,李长青.LTE网络切换密钥更新方案分析与改进[J].无线电工程,2017,47(01):10-15.
基金信息: