论文部分内容阅读
个人通信系统(PCS)的智能网络层上每个结点的数据库采用全分布式结构。根据PCS的智能层数据库结构特点以及X.509目录认证架构,提出了一种移动用户登记认证方案。此方案克服了X.509所具有的“静态”特性,使其能够满足PCS用户移动性及终端移动性的要求。在进行用户登记认证的同时,用户与本地的访问网络之间还建立起一个秘密数据。基于这一秘密数据,用户与网络之间可以在呼叫建立阶段进行相互认证。这就避免了现有的移动通信系统(如GSM,IS-41等)呼叫建立阶段的认证受归属网位置登记数据库(HLR)控制的缺陷。因此,用于位置修订和查询的信令负荷大大减小;同时,有关骨干网络(如PSPDN或共路信令网)安全的假定也可以被取消。
The database for each node on the intelligent network layer of the Personal Communications System (PCS) is fully distributed. According to PCS intelligent layer database structure and X.509 directory authentication architecture, a mobile user registration authentication scheme is proposed. This solution overcomes the “static” nature of the X.509, enabling it to meet the mobility and end-user mobility requirements of PCS users. While conducting user registration authentication, a secret data is also established between the user and the local access network. Based on this secret data, the user and the network can authenticate each other during the call setup phase. This avoids the disadvantage that the authentication of the call establishment phase of the existing mobile communication system (such as GSM, IS-41, etc.) is controlled by the home network location registration database (HLR). As a result, the signaling load for location revising and polling is greatly reduced; at the same time, assumptions about the security of backbone networks such as the PSPDN or the common signaling network can also be eliminated.