From: Simon Wunderlich <simon.wunderlich@s2003.tu-chemnitz.de>
To: The list for a Better Approach To Mobile Ad-hoc Networking
<b.a.t.m.a.n@lists.open-mesh.org>
Subject: Re: [B.A.T.M.A.N.] Security & node authentication in BATMAN network
Date: Mon, 26 Apr 2010 00:01:10 +0200 [thread overview]
Message-ID: <20100425220110.GA6186@pandem0nium> (raw)
In-Reply-To: <201004252136.25395.adebex@gmail.com>
[-- Attachment #1: Type: text/plain, Size: 2200 bytes --]
Hello Adrian,
quite good answers have already been on the list. Maybe it is helpful to
create VLANs for your purpose on top of the mesh, e.g.:
1. An open patient/customer VLAN for internet traffic etc
2. a hospital internal VLAN for your sensitive information
3. an administration VLAN for maintainance on your nodes
These VLANs should be configured ontop of the meshnodes and should be
controlled by the nodes, means that the patients should not be able to
access the internal VLAN.
Additionally, you should secure the mesh with WPA-NONE, but as
stated before the security of this method is not well researched and
might be weaker than WPA2/CCMP. It basically use static keys with either
TKIP or CCMP(AES).
best regards,
Simon
On Sun, Apr 25, 2010 at 09:36:25PM +0200, Adrian Byszuk wrote:
> Hello,
>
> I'm currently working on project (part of my Bachelor work) which will use to
> transfer very sensitive data over the network, and I'd like to use mesh
> networks to transfer this data. Additionally, it should also be possible for
> "normal people" to connect to this network (e.g. to surf internet).
> Preliminary, I've chosen BATMAN to build this network. But I've got a few
> questions regarding security of this solution:
>
> 1. Does BATMAN provide any method of *authenticating* nodes?
> As I've said earlier, sometimes transferred data will be highly sensitive (for
> example: information of patients health in hospital), so it's absolutely
> critical to not allow leaking this information. I can imagine situation when
> some fake nodes claim "Hey, I'm the server collecting this data"...
> I think this is also important when someone would try to destroy our mesh
> network by placing some fake nodes in it.
> 2. If point nr one isn't possible, maybe there is some other way to ensure
> security? I don't know too much about security or cryptography, but I can
> think of solutions such as openVPN or IPsec.
>
> Generally, the goal is to assert security of transmitting some data *without*
> losing open characteristics of mesh network.
>
> I will very thankful for any answers.
>
> Kind regards,
> Adrian
>
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 197 bytes --]
prev parent reply other threads:[~2010-04-25 22:01 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-04-25 19:36 [B.A.T.M.A.N.] Security & node authentication in BATMAN network Adrian Byszuk
2010-04-25 19:53 ` Andrew Lunn
2010-04-25 20:08 ` Sven Eckelmann
2010-04-25 20:13 ` Daniel Golle
2010-04-25 21:14 ` Marek Lindner
2010-04-25 23:24 ` Adrian Byszuk
2010-04-26 5:14 ` Andrew Lunn
2010-04-25 21:07 ` Marek Lindner
2010-04-25 22:01 ` Simon Wunderlich [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100425220110.GA6186@pandem0nium \
--to=simon.wunderlich@s2003.tu-chemnitz.de \
--cc=b.a.t.m.a.n@lists.open-mesh.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.