摘要
随着网络技术的发展,各类新型网络协议层出不穷。然而,当前异构网络缺乏完善、有效的安全机制,数据传输过程中面临着隐私泄露的风险,可能带来一系列安全问题。针对上述挑战,该文提出了一种协议无关的灵活加密传输机制(PIFET),通过提高数据的机密性和加密的灵活性,进一步保障异构数据的通信安全。首先,基于可编程平台设计了面向异构协议的灵活加密传输的系统架构;在此基础之上,根据异构数据的传输需要和安全需求,实现了灵活的加密机制,提供了两种不同安全等级的加密方法;最后,提出了面向隧道模式的字段灵活可选的加密机制。实验结果表明,PIFET为用户提供了多种安全级别的、可定义的加密方法,满足了不同数据类型的加密需求。字段灵活可选的加密机制减少了不必要的加密量,从而降低了延迟,提高了系统的时间效率。
With the development of network technology,various new network protocols have emerged.However,current heterogeneous networks lack perfect and effective security mechanisms,and face the risk of privacy leakage during data transmission.To address the above challenges,we propose a protocol-independent flexible encrypted transmission mechanism(PIFET)to further secure the communication of heterogeneous data by improving the confidentiality of data and the flexibility of encryption.Firstly,we design a system architecture for flexible encrypted transmission of heterogeneous protocols based on a programmable platform.Besides,a flexible encryption mechanism is implemented according to the transmission needs and security requirements of heterogeneous data,and two encryption methods with different security levels are provided.Finally,a fields-flexible optional encryption mechanism oriented to tunnel mode is proposed.The experimental results show that PIFET provides users with multiple security levels and definable encryption methods to meet the encryption needs of different data types.The fields-flexible optional encryption mechanism of the fields reduces the amount of unnecessary encryption thus reducing the latency and improving the time efficiency of the system.
作者
刘泽英
崔鹏帅
胡宇翔
董永吉
王钰
李子勇
LIU Ze-ying;CUI Peng-shuai;HU Yu-xiang;DONG Yong-ji;WANG Yu;LI Zi-yong(Institute of Information Technology Research,People’s Liberation Army Strategic Support Force Information Engineering University,Zhengzhou 450000,China)
出处
《计算机技术与发展》
2023年第11期106-112,共7页
Computer Technology and Development
基金
国家重点研发计划(2022YFB2901403)
嵩山实验室项目(221100210900-02)。
关键词
SDN
可编程数据平面
灵活加密
异构协议
安全策略
SDN
programmable data plane
flexible encryption
heterogeneous protocols
security policy