Monitoring-Based Key Revocation Schemes for Mobile Ad Hoc Networks: Design and Security Analysis

Katrin Hoeper, Guang Gong · 2012

This article proposes a parameterized trust model and security analysis framework for monitoring-based schemes that enables the identification of malicious nodes in mobile ad hoc networks (MANETs) and other decentralized networks. We utilize these results to design a practical decentralized key revocation scheme for MANETs in which nodes monitor their neighbors and securely propagate their observations, where security thresholds δ and ε protect against false accusations from groups of malicious nodes. Our revocation scheme is the first of its kind to take the inaccuracy of the underlying monitoring scheme into account. For example, we derive upper bounds for false positive rate α and false negative rate β that ensure the functionality and security of the revocation scheme. By utilizing security parameters δ, ε, α and β, we provide an extensive security analysis showing how to select these and other system parameters to mitigate a wide range of attacks from insiders and outsiders as well as colluding nodes. Key words: Mobile ad hoc networks, security, monitoring, key revocation, identity-based cryptography.

Read the paper · More papers on PaperTik