In vehicular ad hoc network (VANET), misbehaviors of internal nodes, such as discarding packets, may lead to a rapid decline in packet delivery ratio. To solve this problem, an improvement of greedy perimeter stateless routing (GPSR) protocol is presented. In the new protocol, trustworthiness is considered in the route selection process. The trustworthiness is measured by an objective trust model based on the subjective trust model DyTrust. And the reputation value which reflects the trustworthiness of each node is calculated and broadcasted by the intersection nodes. Specially, besides resisting the packet-discarding behavior of selfish nodes, this protocol also includes a location detection process to resist the location-faking behavior of malicious nodes. As a result, the selfish nodes and the malicious nodes can be excluded from the network. In addition, compared with improved GPSR protocol, the presented one is able to resist one kind of reputation-faking attack and has better performance in simulation.
Trust management has been proven to be a useful technology for providing security service and as a consequence has been used in many applications such as P2P, Grid, ad hoc network and so on. However, few researches about trust mechanism for Internet of Things (IoT) could be found in the literature, though we argue that considerable necessity is held for applying trust mechanism to IoT. In this paper, we establish a formal trust management control mechanism based on architecture modeling of IoT. We decompose the IoT into three layers, which are sensor layer, core layer and application layer, from aspects of network composition of IoT. Each layer is controlled by trust management for special purpose: self-organized, affective routing and multi-service respectively. And the final decision-making is performed by service requester according to the collected trust information as well as requester' policy. Finally, we use a formal semantics-based and fuzzy set theory to realize all above trust mechanism, the result of which provides a general framework for the development of trust models of IoT.
由于边界网关协议(Border Gateway Protocol, BGP)存在安全问题,路径信息(AS_PATH属性)易遭受各种攻击。已有的路径验证方案中,过程复杂和开销巨大严重阻碍了方案的实际部署。基于对AS_PATH属性的分析,该文提出一种轻量化的BGP路径验证机制FTAPV(First-Two-AS based Path Verification)。FTAPV中,更新报文只需要携带AS_PATH中前两个AS的签名信息就可以有效地为路径信息提供保护。安全分析和性能评估表明,与已有方案相比,该机制在保证安全能力的同时,有效地减少了路由资源的消耗和所需证书的规模,具有良好的可扩展性。
A distributed trust model based on parameter modeling was proposed. Nine functional parameters were ex-tracted after investigating the trust mechanism and current trust models. These parameters included flexibility, subjectivity, fuzziness, time decay property, transitivity, anti-attacks property, rewards & punishment property, sensitivity and scalability. Each parameter was modeled and integrated to form a comprehensive trust model. Analytical results indicate that the pro-posed trust model satisfies all the nine functional parameters and thus has fair universality. Experimental results show that the proposed trust model is reasonable and effective. Comparisons with previous algorithms indicate that the performance of the proposed trust model has been improved.
Trust management provides a potential solution for the security issues of distributed networks. However, there are rare researches about the trust mechanism for IoT in the literature. A new distributed trust management mechanism for IoT is established in this paper. Firstly, we extract three basic elements-service, decision-making and self-organizing, of trust management from the investigated trust solutions. Then, based on a service model, we establish a trust management frame-work for the layered IoT, which is decomposed into three layers: sensor layer, core layer and application layer. Finally, we use fuzzy set theory and formal semantics-based language to perform the layered trust mechanism. The proposed trust conception, layered service model and formal method provide a general framework for the study of trust management for the IoT, and further provide a significant reference for the development of sound trust models for IoT.
In order to sign the vary age value and check its verification.A new secure protection mechanism for open shortest path first(OSPF) routing protocol is proposed through utilizing the sanitizable signature scheme.Enhanced sanitizable signature schemes,combines with the security property of weak transparence on the sanitizable signature algorithm,to protect the routing massage on the OSPF protocol.Security analysis shows,the proposed OSPF protocol can avoid the MaxAge attack and premature MaxAge attack.
P2P network has become an important branch of Internet recently, with the significant advantages of full resource utilization, dynamics, openness and high scalable, which helps it achieve wide applications. But security and trust have also become urgent problems for a P2P network due to its openness and anonymousness. Most of the current schemes rely on some trust models, but the research in systematic managing scheme is scarce. Consequently, we propose a scheme of constructing trust management systems in a P2P network here.
This paper presents a trust-based QoS management implementation to assure trust and security of the IP network. In this architecture, every IP packet is forwarded and queued by its trust-value, which is the quantification of the network's expectation of this packet's behavior in networks. We also outlined the deployment of the trusted routers which carry out this algorithm. At last we provide the simulation results of this algorithm to illustrate the effects of this implementation.
In ESS2008, Yang et aI. suggested a key-exposurefree chameleon hashing scheme, and it can be used to design signature and some other cryptography mechanism. In this paper, we construct a new timeliness optimistic fair exchange protocol based on this key-exposure-free chameleon hashing scheme. The new scheme does not require the use of interactive zero-knowledge proofs in the exchange phase. In our scheme, both parties can contact the trusted third party and settle the argument before the deadline. Moreover, the new scheme achieves fairness and timeliness.
Intergrated the factors that state and behavior of entities,a new dynamic trust model of trusted network was proposed.The trust information was obtained through the associated analysis of state and behavior of entities.The rela-tion of trust,state and behavior of the entities was also studied,and a new dynamic trust measurement of trusted network was proposed.The simulation results show that the new trust model has advantages in providing real-time dynamic trust.It is highly effective in countering malicious entities regarding strategic altering behavior and malicious attack,presenting better choice in task assignment in the network,providing help to make the secure police for the network security,and enhancing trustworthily of network.
Router has acted as more and more important role in the large-scale network. In the meantime, the security of the router become more seriously. In this paper, we propose a new algorithm to decide a credential routing path from the start router to the end one based on the trust theory that considers the trustworthy of link, the cost of link and the trustworthy of router as the critical factors so as to utilize the principle of the grey correlation degree to obtain a credential routing path, instead of weighted mean in existed methods of trust measurement. We guarantee that packet can secure transfer under the credential routing path and identify the remote routers that are subject to attacks.
Group-oriented services are attractive to both customers and service providers since they allow for potential markets that exploit user collaboration and shared experiences. In order to protect the content of a group service, the content must be encrypted using a key shared by group members. With the advancement of network technologies, customers will access group services from different networks using different terminals. The computational capabilities of the group members will vary. Contributory key agreement schemes have been developed to support secure communication between many senders and many receivers, but do not consider that users might require different amounts of time to perform a round of key establishment. In this paper, we develop a contributory key agreement scheme to setup the customer group which achieves a smaller latency for group key generation than existing schemes. We then address the latency needed to rekey the group during member joins and departures. A protocol that determines the location to place a joining member is presented that considers the time needed for rekeying the joining member as well as the effect the joining member has upon the departure times of the other group members. Simulations are presented that compare our algorithms with existing schemes for different group sizes, as well as different user join rates.