<p>As more and more Internet of Thing (IoT) devices directly access to low earth orbit (LEO) satellite networks, the Zero-Trust Architecture brings dynamic security to the enlarging exposure surface. However, the constrained resources of satellites add difficulties to the dynamic management of the edge access network. In order to balance the scalability and security of the satellite-ground zero-trust system, this paper proposes a high-scalable authentication model (Hi-SAM). Hi-SAM introduces the Proof-of-Work idea to bind authentications number and communication resource, which transforms the management problem to a resources competition game. And a first-order mean field game is used to reduce the decision space of large-size population competition. Moreover, considering the selfish nodes in the population that do not cooperate with the management, a dynamic time-range message authentication code with penalty policy is designed. From the test at large size population, Hi-SAM is superior in the optimization of authentication workload and the anomaly detection efficiency.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Hi-SAM: A High-Scalable Authentication Model for Satellite-Ground Zero-Trust System Using Mean Field Game

  • Xuesong Wu,
  • Tianshuai Zheng,
  • Runfang Wu,
  • Jie Ren,
  • Junyan Guo,
  • Ye Du

摘要

As more and more Internet of Thing (IoT) devices directly access to low earth orbit (LEO) satellite networks, the Zero-Trust Architecture brings dynamic security to the enlarging exposure surface. However, the constrained resources of satellites add difficulties to the dynamic management of the edge access network. In order to balance the scalability and security of the satellite-ground zero-trust system, this paper proposes a high-scalable authentication model (Hi-SAM). Hi-SAM introduces the Proof-of-Work idea to bind authentications number and communication resource, which transforms the management problem to a resources competition game. And a first-order mean field game is used to reduce the decision space of large-size population competition. Moreover, considering the selfish nodes in the population that do not cooperate with the management, a dynamic time-range message authentication code with penalty policy is designed. From the test at large size population, Hi-SAM is superior in the optimization of authentication workload and the anomaly detection efficiency.