5G-WLAN Security 157
from any intentional or accidental changes. Integrity has been used for a long time in
computer systems to attain three important goals, namely:
1) To protect data by prohibiting unauthorized user access to make any modifications
to user data or network data;
2) To prohibit authorized users from making unauthorized modifications; and
3) To prevent internal and external consistency of data and programs [20].
There are two ways to measure the data integrity, criticality and credibility. Criticality can
be described as the system that does not tolerate failures for internal and external events.
Credibility can be described as something that is believed to have a degree of trust in place.
7.5.3 Mutual Authentication and Key Management
Password‐based authentication is the most widely‐used method for remote user authentication. Existing methodologies can be classified into two types, namely: (i) weak password
approach; and (ii) strong password approach. The ElGamal cryptosystem is based on the
weak password approach, where its advantage depends on the fact that it does not require
a user ID‐password table to check and verify the user login validity. On the other hand, the
weak password approach depends on a heavy computational load on the node that
constrains devices’ (IoT) lack of capacity, which results in the difficulty in rendering 5G
networks. One‐way hash function and exclusive‐OR (XOR) operations are being proposed
as a strong password approach. In 2004, a dynamic ID‐based remote user authentication
scheme was proposed [21]. Based on this explanation, it requires much less computation
and does not require any complex operations. Due to these reasons, this kind of proposed
scheme certainly has advantages when implemented in constrained networks.
Key management plays a pivotal role in enforcing access control on the group key and
in group communication. In addition, key management supports the establishment and
maintenance of key relationships between valid groups based on the security policy
being enforced on the corresponding group. The techniques and procedures that can
carry out key management protocols are:
● Member identification and authentication: Authentication is a key factor to prevent
an intruder from impersonating a legitimate group member. Furthermore, it is
significant to prevent attackers from impersonating key managers. This clearly states
that authentication mechanisms must be used to allow an entity to verify whether
another entity is really who it claims to be [22].
● Access control: Once a group is identified, its joint operation should be validated.
Access control will be performed in order to validate the group members before
giving them access to group communication, particularly for the group key.
● Generation, distribution and installation of keys: It is a prerequisite to change the key
at regular intervals to safeguard the secrecy of the key. In addition, extra care must be
taken while choosing a new security key to guarantee key independence. Furthermore,
each key must be completely independent from any of the previously used keys and
keys going to be used in the future. Otherwise, compromised keys may reveal other
keys that will create a security loop‐hole.
In centralized techniques, a single entity is employed to control the whole group.
Hence, a group key management protocol seeks to minimize storage requirements and
computational power in both client and server.
Précédent

- 199/483

Suivant