Journal of Software:2011.22(5):1009-1019

拓扑隐藏的MANET 安全多路径路由协议
(中国科学院 计算技术研究所 网络技术研究中心,北京 100190;中国科学院 研究生院 信息科学与工程学院,北京 100049)
Topology-Hiding Secure Multipath Routing Protocol for MANET
HU Qi,ZHANG Jiao,ZHANG Yu-Jun,LI Zhong-Cheng
(Network Technology Research Center, Institute of Computing Technology, The Chinese Academy of Sciences, Beijing 100190, China; School of Information Science and Engineering, Graduate University, The Chinese Academy of Sciences, Beijing 100049, China)
Received:December 24, 2008    Revised:November 26, 2009
> 中文摘要: 分析了移动自组网(mobile ad hoc network,简称MANET)暴露拓扑带来的安全问题,提出了一种拓扑隐藏的安全多路径路由协议.在路由发现过程中,不在路由包中携带任何路径信息,从而有效隐藏网络拓扑.通过按需的邻居发现进行身份认证并建立路由表项,最终采用排除节点的方法实现多路径的选取;在路由维护过程中,设计了专门的错误发现机制以检验所选路径的有效性和安全性.该协议综合考虑时间因素和路径长度因素,实现了安全的最短路径确定.安全分析表明,该方案可以抵御黑洞攻击、虫洞攻击、rushing 攻击和sy
Abstract:This paper provides a detailed analysis on the threats of topology-exposure in Mobile Ad Hoc Network (MANET) and proposes a secure topology-hiding multipath routing protocol based on the analysis. In Route Discovery, the new protocol exposes no routing information in packets to hide the network topology and adopts a node-excluded mechanism to find multiple paths. During this process, this protocol implements on-demand Neighbor Discovery to verify node identities. In Route Maintenance, a fault detection mechanism is designed to provide assurance that the selected paths are available and secure. Considering the factors of both reaction time and the path length, the scheme aims to find the shortest secure path. The security analysis shows that this scheme can resist the black hole attack, the wormhole attack, the rushing attack, the sybil attack, and other types of common attacks. Through extensive simulations, results demonstrate that this approach can find many more active paths than SRP without bringing negative influences into the normal scenario. Furthermore, this solution largely improves the packet delivery ratio in the black hole attack scenario at an acceptable cost.
基金项目:国家自然科学基金(60803139); 国家科技支撑计划(2008BAH37B07) 国家自然科学基金(60803139); 国家科技支撑计划(2008BAH37B07)
Foundation items:
胡琪,张娇,张玉军,李忠诚.拓扑隐藏的MANET 安全多路径路由协议.软件学报,2011,22(5):1009-1019

HU Qi,ZHANG Jiao,ZHANG Yu-Jun,LI Zhong-Cheng.Topology-Hiding Secure Multipath Routing Protocol for MANET.Journal of Software,2011,22(5):1009-1019