首页> 外国专利> METHODS TO STRENGTHEN CYBER-SECURITY AND PRIVACY IN A DETERMINISTIC INTERNET OF THINGS

METHODS TO STRENGTHEN CYBER-SECURITY AND PRIVACY IN A DETERMINISTIC INTERNET OF THINGS

机译:确定性物联网中增强网络安全性和私密性的方法

摘要

Methods to strengthen the cyber-security and privacy in a proposed deterministic Internet of Things (IoT) network are described. The proposed deterministic IoT consists of a network of simple deterministic packet switches under the control of a low-complexity ‘Software Defined Networking’ (SDN) control-plane. The network can transport ‘Deterministic Traffic Flows’ (DTFs), where each DTF has a source node, a destination node, a fixed path through the network, and a deterministic or guaranteed rate of transmission. The SDN control-plane can configure millions of distinct interference-free ‘Deterministic Virtual Networks’ (DVNs) into the IoT, where each DVN is a collection of interference-free DTFs. The SDN control-plane can configure each deterministic packet switch to store several deterministic periodic schedules, defined for a scheduling-frame which comprises F time-slots. The schedules of a network determine which DTFs are authorized to transmit data over each fiber-optic link of the network. These schedules also ensure that each DTF will receive a deterministic rate of transmission through every switch it traverses, with full immunity to congestion, interference and Denial-of-Service (DoS) attacks. Any unauthorized transmissions by a cyber-attacker can also be detected quickly, since the schedules also identify unauthorized transmissions. Each source node and destination node of a DTF, and optionally each switch in the network, can have a low-complexity private-key encryption/decryption unit. The SDN control-plane can configure the source and destination nodes of a DTF, and optionally the switches in the network, to encrypt and decrypt the packets of a DTF using these low-complexity encryption/decryption units. To strengthen security and privacy and to lower the energy use, the private keys can be very large, for example several thousands of bits. The SDN control-plane can configure; each DTF to achieve a desired level of security well beyond what is possible with existing schemes such as AES, by using very long keys. The encryption/decryption units also use a new serial permutation unit the very low hardware cost, which allows for exceptional security and very-high throughputs in FPGA hardware.
机译:描述了在提议的确定性物联网(IoT)网络中增强网络安全性和隐私性的方法。拟议的确定性物联网由在低复杂度的“软件定义网络”(SDN)控制平面的控制下的简单确定性分组交换机网络组成。网络可以传输“确定性流量”(DTF),其中每个DTF都有一个源节点,一个目标节点,通过网络的固定路径以及确定的或保证的传输速率。 SDN控制平面可以在物联网中配置数百万个不同的无干扰“确定性虚拟网络”(DVN),其中每个DVN都是无干扰DTF的集合。 SDN控制平面可以将每个确定性数据包交换机配置为存储几个确定性定期调度,这些定期调度是为包含F个时隙的调度帧定义的。网络的时间表确定哪些DTF被授权通过网络的每个光纤链路传输数据。这些时间表还确保每个DTF通过其所经过的每个交换机都将获得确定的传输速率,并且完全不受拥塞,干扰和拒绝服务(DoS)攻击的影响。由于时间表还可以识别未经授权的传输,因此也可以快速检测到网络攻击者的任何未经授权的传输。 DTF的每个源节点和目标节点,以及网络中的每个交换机(可选)可以具有低复杂度的私钥加密/解密单元。 SDN控制平面可以配置DTF的源节点和目标节点,并可选地配置网络中的交换机,以使用这些低复杂度的加密/解密单元对DTF的数据包进行加密和解密。为了增强安全性和隐私性并降低能耗,私钥可能非常大,例如数千位。 SDN控制平面可以配置;通过使用非常长的密钥,每个DTF都可以达到远远超过现有方案(例如AES)所能达到的安全级别。加密/解密单元还使用了一种新的串行置换单元,其硬件成本非常低,从而在FPGA硬件中具有出色的安全性和很高的吞吐量。

著录项

  • 公开/公告号US2019044920A1

    专利类型

  • 公开/公告日2019-02-07

    原文格式PDF

  • 申请/专利权人 TED H. SZYMANSKI;

    申请/专利号US201716075402

  • 发明设计人 TED H. SZYMANSKI;

    申请日2017-02-03

  • 分类号H04L29/06;H04L9/14;H04L9/08;H04L12/937;H04L12/851;H04L12/873;H04L12/863;H04L12/935;H04L12/933;H04L29/08;

  • 国家 US

  • 入库时间 2022-08-21 12:04:04

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号