基于LTE的智慧標(biāo)識移動(dòng)專網(wǎng)服務(wù)安全訪問機(jī)制設(shè)計(jì)與實(shí)現(xiàn)
[Abstract]:With the rapid development of information technology, Internet not only brings many convenience to people's life, but also brings many security problems because of the defects of its original design. In order to overcome the disadvantages of traditional Internet fundamentally, the National Engineering Laboratory of next Generation Internet Interconnection equipment has put forward a new network architecture of intelligent marking network, which has better security and expansibility. At the same time, the scale of access to the Internet through mobile terminals is increasing year by year. The core network of LTE (Long Term Evolution, the mainstream technology of 4G era, adopts full IP architecture, which makes it possible to integrate new networks. The research of this paper is based on the research on the application of identification network technology in mobile private network, and designs and implements a set of secure access mechanism of service in the intelligent identification mobile private network based on LTE, which is based on the important security special project "the application of marking network technology in mobile private network". At the same time, fine-grained service security access control and protection are carried out for mobile users, which further ensures the security of identifying network service resources and improves the efficiency of mobile users' access to services. This paper mainly studies the design and implementation of secure access mechanism of intelligent identification mobile private network service based on LTE. Firstly, this paper gives an overview of LTE and intelligent identification network, and introduces the protocol principle of adding service acquisition function to mobile communication network. Then this paper analyzes the requirements and the scheme design of the service security access mechanism, and then explains the implementation method of each module from the point of view of code. The main design and implementation of this paper are as follows: through the design and implementation of the service matching module and the service cache module in the LTE core network, the mobile users' functional requirements of getting the service close to the LTE core network have been completed; Through parsing server SID (Service Identifier, service identification) parsing module, identification mapping module on PGW and the design and implementation of identity-specific network routing mechanism, the fine-grained service access control for users and RID (Router Identifier,-based service access control have been completed. Routing (routing identification) ensures the security of service resources and reduces routing redundancy in private networks; Through the design and implementation of user service reputation management table, user service management information interaction in control layer and detection and defense mechanism of mobile user attack behavior, the detection and defense of service-based DOS attack is completed. Guarantee the performance security of the analysis server and the reliability of the normal user to obtain the service. Finally, this paper builds a test environment to test the function and performance of the security access mechanism. The test results verify the basic functions of the service security access mechanism, solve the demand of the mobile users to obtain the service nearby, and enhance the security of the service resources and the reliability of the mobile users' access to the service resources. Finally, the paper summarizes the full text, which lays a good foundation for the follow-up work.
【學(xué)位授予單位】:北京交通大學(xué)
【學(xué)位級別】:碩士
【學(xué)位授予年份】:2017
【分類號】:TN929.5
【參考文獻(xiàn)】
相關(guān)期刊論文 前10條
1 孫其博;;移動(dòng)互聯(lián)網(wǎng)安全綜述[J];無線電通信技術(shù);2016年02期
2 劉斌;汪漪;;內(nèi)容中心網(wǎng)絡(luò)中名字查找技術(shù)的研究[J];電信科學(xué);2014年09期
3 張宏科;陳哲;;智慧協(xié)同標(biāo)識網(wǎng)絡(luò)[J];中興通訊技術(shù);2014年04期
4 蘭巨龍;程東年;胡宇翔;;可重構(gòu)信息通信基礎(chǔ)網(wǎng)絡(luò)體系研究[J];通信學(xué)報(bào);2014年01期
5 陳小晨;;電信運(yùn)營商互聯(lián)網(wǎng)業(yè)務(wù)解決方案探索[J];科技廣場;2013年09期
6 張宏科;黃道超;;智慧標(biāo)識網(wǎng)絡(luò)的未來互聯(lián)網(wǎng)體系[J];電信科學(xué);2013年S1期
7 蘇偉;陳佳;周華春;張宏科;;智慧協(xié)同網(wǎng)絡(luò)中的服務(wù)機(jī)理研究[J];電子學(xué)報(bào);2013年07期
8 郜帥;王洪超;王凱;張宏科;;智慧網(wǎng)絡(luò)組件協(xié)同機(jī)制研究[J];電子學(xué)報(bào);2013年07期
9 張宏科;羅洪斌;;智慧協(xié)同網(wǎng)絡(luò)體系基礎(chǔ)研究[J];電子學(xué)報(bào);2013年07期
10 蘇偉;劉琪;張宏科;;一體化標(biāo)識網(wǎng)絡(luò)體系及關(guān)鍵技術(shù)[J];中興通訊技術(shù);2011年02期
,本文編號:2446528
本文鏈接:http://www.wukwdryxk.cn/kejilunwen/xinxigongchenglunwen/2446528.html