Abstract
Wireless ad hoc networks have been applied in many areas, including military communications, emergency search, rescue operations, and data acquisition. Information in a wireless ad hoc network that needs confidentiality protection includes location information and message content. In this dissertation, for confidentiality of location information and message content, we study three issues of confidentiality protection in wireless ad hoc networks: (1) confidentiality protection of location information in wireless sensor networks, (2) confidentiality protection of message content in wireless sensor networks, (3) confidentiality protection of message content in group communication of mobile ad hoc networks. In the first and second issues of this dissertation, we focus on wireless sensor networks, which are a form of wireless ad hoc networks. For a wireless sensor network, a heterogeneous structure is frequently used to improve communication efficiency and prolong life time of the wireless sensor network. In a heterogeneous structure, a wireless sensor network consists of critical sensors and normal sensors. A critical sensor usually plays an important role in a heterogeneous wireless sensor network. Therefore, confidentiality protection for information of critical nodes in a heterogeneous wireless sensor networks is an important issue. Furthermore, to prevent a sink node that collects acquired data being compromised by an adversary, a sink is usually not constantly present in the network. Therefore, with these features, sensors need to store acquired data during a period that a sink is absent. Once a critical sensor is compromised, there should a mechanism to recover damage caused by compromise of the critical node. In the first issue, we found a trade-off between data survivability and location privacy when a strategy of data replication is used to defeat an adversary that attempts to compromise and delete the acquired data in the sensors. We consider a new kind of adversary that, by using specific location estimation schemes, attempts to derive location information of a critical node based on the locations of the compromised sensors that store the data replicas. Under this kind of attack, the number of data replicas of the acquired data should be limited. We propose three possible location estimation schemes to demonstrate the trade-off relationship in a grid-based unattended wireless sensor network. According to simulation results, the number of data replicas must be limited when considering data survivability and location privacy at the same time. In the second issue, we focus on a typical heterogeneous wireless sensor network: a cluster-based wireless sensor network. In a cluster-based wireless sensor network, a cluster head is a critical node. We propose a self-healing cluster key management scheme to recover secure inter-cluster communication when any cluster head is compromised. In the self-healing cluster key management scheme, when a cluster head is compromised, a specific sensor in the cluster of the compromised cluster head is chosen as a successor to replace the compromised cluster head. Other cluster heads sponsor specific keying materials to the chosen sensor to reconstruct a key generation function. Through security analysis, we derive a parameter setting to enhance the security of our scheme. Simulation results show that our scheme significantly improves the number of available nodes by about 75% when 50% of the entities are compromised. In the third issue, we focus on the confidentiality of the message content for a group of members in mobile ad hoc networks. Existing group key agreements need messages in large sizes to generate and refresh the group key, but we propose a group key agreement that reduces the size of the message needed to generate or refresh the group keys. Through security analysis, we show that our group key agreement satisfies the security requirements of a group key agreement. Simulation results show that our group key agreement can provide lower communication overhead and lower latency of generating or refreshing a group key compared with the existing contributory group key agreements. When a new member joins the group, our scheme requires fewer packets to be sent and forwarded. When an existing member leaves, our scheme requires a smaller number of packets to be sent and forwarded when the current group size is large.