User plane security alternatives in the 3G evolved Multimedia Broadcast Multicast Service (e-MBMS)

被引:2
作者
Teofili, Simone [1 ]
Di Mascolo, Michele [1 ]
Basile, Cristina [1 ]
Bianchi, Giuseppe [1 ]
Salsano, Stefano [1 ]
Zugenmaier, Alf [2 ]
机构
[1] Univ Roma Tor Vergata, Dipartimento Ingn Elettron, Rome, Italy
[2] DoCoMo Euro Labs, Munich, Germany
关键词
Multicast broadcast multimedia services; 3GPP; MBMS security;
D O I
10.1002/sec.73
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The 3GPP architecture includes the Multimedia Broadcast Multicast Service (MBMS) to provide efficient broadcast and multicast services. In the 3GPP long-term evolution, the evolved MBMS (e-MBMS) architecture is currently being standardized. Unlike MBMS, the new e-MBMS architecture explicitly raises, as additional security requirement, the protection of the IP multicast user plane. Currently proposed e-MBMS security architectures "limit" themselves to suggest the deployment of Group Security Associations (GSA). In this paper, we start by discussing that, on one side, GSA might not be a sufficiently secure solution in the long run, and on the other side GSA integration within the e-MBMS architecture might not be as straightforward as it might appear. The point made in this paper is that there are sound alternatives to GSA if the goal is to deploy a short-term solution with basically no impact on the current e-MBMS architecture. In particular, we propose to adopt a Secure Multicast Overlay (SMO) approach. To prove the straightforward implementation of SMO we describe how a proof-of-concept test-bed over public domain linux routers. Moreover, a functional comparison between GSA and SMO leads us to the following conclusions: (i) not only SMO provides the same level of security of GSA, but also it achieves a reduced risk of denial of service attacks; (ii) SMO has significant advantages over GSA in terms of impact on the architecture and on device requirements; (iii) security association management and key management in GSA has a greater impact on the performance achievable than in the case of SMO. We believe that these advantages outweigh the performance penalties due to overlay networking overhead. Copyright (C) 2008 John Wiley & Sons, Ltd.
引用
收藏
页码:473 / 485
页数:13
相关论文
共 26 条
  • [1] *3G PP, 2007, S3070618 3G PP
  • [2] *3GPP, 2008, 33246V800 3GPP TS
  • [3] *3GPP, 2008, 36300V840 3GPP TS
  • [4] *3GPP, 2008, 26346V770 3GPP TS
  • [5] *3GPP, 2007, TSGSA3 3GPP
  • [6] Adrian P., 2005, RFC, V4082, P1
  • [7] [Anonymous], 302304V111 ETSI EN
  • [8] [Anonymous], 4046 IETF RFC
  • [9] Bollapragada V., 2005, IPSec VPN Design
  • [10] A TAXONOMY OF MULTICAST DATA ORIGIN AUTHENTICATION: ISSUES AND SOLUTIONS
    Challal, Yacine
    Bettahar, Hatem
    Bouabdallah, Abdelmadjid
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2004, 6 (03): : 34 - 57