一种基于量子加密的软件定义网络南向安全防护策略  被引量:4

A Software-defined Network Southward Security Protection Strategy Based on Quantum Encryption

在线阅读下载全文

作  者:谢珲 聂敏 杨光 XIE Hui;NIE Min;YANG Guang(School of Communication and Information Engineering,Xi′an University of Posts and Telecommunication,Xi′an 710121,China;School of Electronics and Information,Northwestern Polytechnical University,Xi′an 710072,China)

机构地区:[1]西安邮电大学通信与信息工程学院,西安710121 [2]西北工业大学电子与信息工程学院,西安710072

出  处:《电讯技术》2020年第9期999-1004,共6页Telecommunication Engineering

基  金:国家自然科学基金资助项目(61971348);陕西省国际科技合作与交流计划项目(2015KW-013)。

摘  要:提出一种以量子加密技术为核心的软件定义网络(Software-defined Network,SDN)的南向安全防护策略,建立了基于量子密钥分发的SDN网络模型并分析了该模型下的身份认证、量子密钥分发和自适应免疫窃听流程。推导出了本策略下窃听攻击强度、用于检测窃听的量子态数目的比例α、系统发现窃听者的概率、密钥分发效率之间的定量关系。通过动态仿真分析确立了不同攻击强度下系统参数α的最优选值区间。SDN控制器可根据该仿真结果,动态地决策系统中α的取值进行自适应免疫密钥分发,实施更为精准的窃听免疫方案。A software-defined network(SDN)security-oriented strategy based on quantum encryption is proposed.The SDN network model based on quantum key distribution is established and the process of identity authentication,quantum key distribution and adaptive immune eavesdropping under the model is analyzed.The quantitative relationship among the strength of eavesdropping attack,the proportionαof quantum states used to detect eavesdropping,the probability of discovering eavesdroppers,and the efficiency of key distribution are derived.Through dynamic simulation analysis,the most preferable value interval for detecting the proportion of the number of eavesdropping particles under different attack strengths is obtained.The SDN controller can dynamically determine the value ofαin the system for adaptive immune key distribution according to the selection interval corresponding to different attack strengths,and a more accurate eavesdropping immunization scheme can be implemented.

关 键 词:软件定义网络 量子密钥分发 自适应免疫 南向安全防护 

分 类 号:TN918[电子电信—通信与信息系统]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象