项目名称: PON网络架构加密机制及时间相关函数算法研究
项目编号: No.61262079
项目类型: 地区科学基金项目
立项/批准年度: 2013
项目学科: 自动化技术、计算机技术
项目作者: 殷爱菡
作者单位: 华东交通大学
项目金额: 48万元
中文摘要: 随着三网融合的推进,PON网络被视为最佳的接入方式。但由于其拓扑结构广播域的特征,传输存在很多安全隐患。为解决PON网络架构下的安全问题,本项目拟通过理论分析和实验计算针对PON网络特点探索一整套严格的安全机制,包括三项内容:针对非法用户的入侵,利用数字签名对OLT/ONU双向认证,并引入密钥交换协议来安全传递初始密钥,杜绝各种非法伪装,保障PON网络合法用户安全;针对各种业务对安全性、实时性的不同需求,设计一个自适应加密算法调度方案,实现业务分级加密,优化系统资源配置;针对安全性要求特别高的数据,利用PON网络测距的机制,结合其时间标签,提出时间相关函数加密算法,为保障此类业务安全提供全新的解决思路。本项目的研究内容为构建PON网络架构安全机制提供理论依据,对大规模应用PON接入的安全具有重要意义。
中文关键词: PON网络;双向认证;时间标签;分级加密;
英文摘要: PON networks are considered as the most promising access means in the incoming Triple Play. However, the security threats, which are caused by the topology and broadcasting feature of PON, hinder its development. To overcome there shortcomings, this research seek a strict scheme by theory analysis and experiments. The contents are as followed. The intrusion and disguise of illegal users can be prevented by using digital signature to bi-directionally authenticate OLT/ONU. And the key exchange protocol is introduced to safely transmit the initial key. As different services require differentiated security and delay time, an adaptive encryption algorithm scheduling mechanism is proposed to implement differentiated services encryption and optimize allocation of system resource. As for the secure-demanding data, the encryption algorithm based on time-related function is presented, providing a whole new thought to guarantee its safety. This research provides theory basis for secure mechanism of PON and has a significant meaning for the safety of massive application of PON.
英文关键词: PON network;bidirectional authentication;;time tag;hierarchical encryption;