The invention provides a two-way access
authentication method for a multi-layer-MAP oriented HMIPv6 network. The two-way access
authentication method comprises the following steps that: a root PKG
server is used as a
trusted third party; a trusted channel is established among the root PKG
server, PKG servers and AR routers in various
layers; the root PKG
server generates common parameters and private keys; the root PKG server issues the private keys to the PKG servers in the various
layers according to identity information of the PKG servers in the various
layers; the PKG server in each layer distributes the private key to the AR
router in this layer according to identity information of the AR
router in this layer; when a mobile node MN leaves a home homework and is accessed to the AR
router under a certain MAP in the HMIPv6 network for the first time, initial two-way access
authentication is carried out; and, when the mobile node MN is in a currently accessed
foreign network and the AR router in the current MAP domain is switched into another MAP domain or another AR router, switching authentication is carried out. The invention provides a
short signature scheme based on node
certificate hierarchical identity; the security is based on the h-CDH problem; the
short signature scheme has the advantages that: the lengths of the private keys are reduced along with increasing of hierarchical levels; and the lengths of the private keys are independent of the hierarchical levels.