A secure and resistant architecture against attacks for mobile ad hoc networks

被引:10
作者
Rachedi, Abderrezak [1 ]
Benslimane, Abderrahim [1 ]
机构
[1] Univ Avignon, LIA CER1, F-84911 Avignon, France
关键词
MANET; security; distributed PKI; trust model; clustering algorithm;
D O I
10.1002/sec.116
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose a new architecture based on an efficient trust model and secure distributed clustering algorithm (SDCA) in order to distribute a certification authority (CA) for ensuring the distribution of certificates in each cluster. We use the combination of a fully self-organized security for trust models like pretty good privacy (PGP) adapted to ad hoc technology and the clustering algorithm which is based on the use of trust and mobility metrics, in order to select the clusterhead and to establish a public key infrastructure (PKI) in each cluster for authentication and exchange of data. Furthermore, we present a new approach: the dynamic demilitarized zone (DDMZ) to protect the CA in each cluster. The principal idea of DDMZ consists in selecting the dispensable nodes, also called registration authorities (RAs); these nodes must be confident and located at one-hope from the CA. Their roles are to receive, filter and treat the requests from any unknown node to the A. With this approach, we can avoid the single point of failure in each cluster. Moreover, we propose a probabilistic model to define the direct connectivity between confident nodes in order to study the resistance degree of the DDMZ against different attacks. In addition, we evaluate the performance of the proposed SDCA and we estimate the robustness and the availability of DDMZ through the simulations. The effects of direct connectivity and transmission range on the stability and security of the network are analyzed. The simulation's results confirm that the proposed architecture is scalable, secure, and more resistant against attacks. Copyright (C) 2009 John Wiley & Sons, Ltd.
引用
收藏
页码:150 / 166
页数:17
相关论文
共 30 条
[1]  
[Anonymous], P MULT MOB TEL WIR C
[2]  
BASU P, 2001, P DISTR COMP SYST WO, P43
[3]  
Bechler M, 2004, IEEE INFOCOM SER, P2393
[4]  
BUDAKOGLU C, 2004, P 2004 IEEE 60 VEH T, V4, P2735
[5]  
CAPKUN S, 2002, P ACM INT WORKSH WIR, P52
[6]  
Chiang CC, 1997, NETWORKS: THE NEXT MILLENNINUM - THE IEEE SINGAPORE INTERNATIONAL CONFERENCE ON NETWORKS 1997, IEEE SICON'97, P197
[7]  
CHOKHANI S, 2003, RFC3647
[8]   Providing distributed certificate authority service in cluster-based mobile ad hoc networks [J].
Dong, Y. ;
Sui, Ai-Fen ;
Yiu, S. M. ;
Li, Victor O. K. ;
Hui, Lucas C. K. .
COMPUTER COMMUNICATIONS, 2007, 30 (11-12) :2442-2452
[9]   Multicluster, mobile, multimedia radio network [J].
Gerla, Mario ;
Tsai, Jack Tzu-Chieh .
WIRELESS NETWORKS, 1995, 1 (03) :255-265
[10]  
GUANG L, 2006, P 9 ACM IEEE INT S M