Xu Liwei, Wu Han, Xie Jianguo, Yuan Qiong, Sun Ying, Shi Guozhen, Luo Shoushan
School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China.
Beijing Electronic Science and Technology Institute, Beijing 100070, China.
Entropy (Basel). 2023 May 6;25(5):760. doi: 10.3390/e25050760.
The Space-Air-Ground Integrated Network (SAGIN) expands cyberspace greatly. Dynamic network architecture, complex communication links, limited resources, and diverse environments make SAGIN's authentication and key distribution much more difficult. Public key cryptography is a better choice for terminals to access SAGIN dynamically, but it is time-consuming. The semiconductor superlattice (SSL) is a strong Physical Unclonable Function (PUF) to be the hardware root of security, and the matched SSL pairs can achieve full entropy key distribution through an insecure public channel. Thus, an access authentication and key distribution scheme is proposed. The inherent security of SSL makes the authentication and key distribution spontaneously achieved without a key management burden and solves the assumption that excellent performance is based on pre-shared symmetric keys. The proposed scheme achieves the intended authentication, confidentiality, integrity, and forward security, which can defend against masquerade attacks, replay attacks, and man-in-the-middle attacks. The formal security analysis substantiates the security goal. The performance evaluation results confirm that the proposed protocols have an obvious advantage over the elliptic curve or bilinear pairings-based protocols. Compared with the protocols based on the pre-distributed symmetric key, our scheme shows unconditional security and dynamic key management with the same level performance.
空天地一体化网络(SAGIN)极大地扩展了网络空间。动态的网络架构、复杂的通信链路、有限的资源以及多样的环境使得SAGIN的认证和密钥分发变得更加困难。公钥密码学是终端动态接入SAGIN的较好选择,但它耗时较长。半导体超晶格(SSL)是一种强大的物理不可克隆功能(PUF),可作为安全的硬件根,并且匹配的SSL对可以通过不安全的公共信道实现全熵密钥分发。因此,提出了一种接入认证和密钥分发方案。SSL的固有安全性使得认证和密钥分发能够自发实现,而无需密钥管理负担,并且解决了基于预共享对称密钥才能实现卓越性能的假设。所提出的方案实现了预期的认证、保密性、完整性和前向安全性,能够抵御伪装攻击、重放攻击和中间人攻击。形式化安全分析证实了安全目标。性能评估结果证实,所提出的协议相对于基于椭圆曲线或双线性配对的协议具有明显优势。与基于预分发对称密钥的协议相比,我们的方案在性能相当的情况下展示了无条件安全性和动态密钥管理。