A Note on an Authentication Technique Based on Distributed Security Management for the Global Mobility Network
Levente Buttyán, Constant Gbaguidi, Sebastian Staamann, U. Wilhelm · Infoscience (Ecole Polytechnique Fédérale de Lausanne) · 1998
In this paper, we analyse the authentication protocol that has been proposed for the so called global mobility network in the October issue of the IEEE Journal on Selected Areas in Communications. Using a simple logic of authentication, we show that the protocol has flaws, and we present three different attacks that exploit these. We correct the protocol using a simple design tool that we have developed. 1 Introduction In a recent issue of the IEEE Journal on Selected Areas of Communications, an authentication technique has been proposed for use in the so called global mobility network (GLOMONET), which provides a personal communication user with global roaming service [SN97]. The proposed authentication technique consists of two phases: Corresponding author. ffl the roaming-service-setup phase, in which authentication to set up the roaming-service environment is performed by the visited (roamed) network, the home network, and the roamer, and ffl the roaming-service-provision phas...