首页> 外国专利> Methods to strengthen cyber-security and privacy in a deterministic internet of things

Methods to strengthen cyber-security and privacy in a deterministic internet of things

机译:在决定性互联网上加强网络安全和隐私的方法

摘要

Methods to strengthen the cyber-security and privacy in a proposed deterministic Internet of Things (IoT) network are described. The proposed deterministic IoT consists of a network of simple deterministic packet switches under the control of a low-complexity ‘Software Defined Networking’ (SDN) control-plane. The network can transport ‘Deterministic Traffic Flows’ (DTFs), where each DTF has a source node, a destination node, a fixed path through the network, and a deterministic or guaranteed rate of transmission. The SDN control-plane can configure millions of distinct interference-free ‘Deterministic Virtual Networks’ (DVNs) into the IoT, where each DVN is a collection of interference-free DTFs. The SDN control-plane can configure each deterministic packet switch to store several deterministic periodic schedules, defined for a scheduling-frame which comprises F time-slots. The schedules of a network determine which DTFs are authorized to transmit data over each fiber-optic link of the network. These schedules also ensure that each DTF will receive a deterministic rate of transmission through every switch it traverses, with full immunity to congestion, interference and Denial-of-Service (DoS) attacks. Any unauthorized transmissions by a cyber-attacker can also be detected quickly, since the schedules also identify unauthorized transmissions. Each source node and destination node of a DTF, and optionally each switch in the network, can have a low-complexity private-key encryption/decryption unit. The SDN control-plane can configure the source and destination nodes of a DTF, and optionally the switches in the network, to encrypt and decrypt the packets of a DTF using these low-complexity encryption/decryption units. To strengthen security and privacy and to lower the energy use, the private keys can be very large, for example several thousands of bits. The SDN control-plane can configure each DTF to achieve a desired level of security well beyond what is possible with existing schemes such as AES, by using very long keys. The encryption/decryption units also use a new serial permutation unit the very low hardware cost, which allows for exceptional security and very-high throughputs in FPGA hardware.
机译:描述了在提出的确定性互联网上加强网络安全和隐私的方法(IOT)网络。所提出的确定性IOT包括在控制低复杂性“软件定义网络”(SDN)控制平面的控制下的简单确定性分组交换机网络。网络可以传输“确定性流量流量”(DTF),其中每个DTF具有源节点,目的节点,通过网络的固定路径,以及确定的或保证的传输速率。 SDN控制平面可以将数百万个不同的无干扰的“确定性虚拟网络”(DVNS)配置为IOT,其中每个DVN是无干扰DTF的集合。 SDN控制平面可以配置每个确定性分组交换机以存储多个确定性定期时间表,用于包括包括F时隙的调度帧。网络的时间表确定哪些DTF被授权在网络的每个光纤链路上传输数据。这些时间表还确保每次DTF都会通过其遍历的每个开关接收确定率的传输速率,充分免疫,拥堵,干扰和拒绝服务(DOS)攻击。也可以快速检测网络攻击者的任何未经授权的传输,因为计划还识别未授权的传输。 DTF的每个源节点和目的节点,以及网络中的每个开关,可以具有低复杂度私钥加密/解密单元。 SDN控制平面可以配置DTF的源和目的地节点,以及可选地,使用这些低复杂性加密/解密单元对DTF的分组进行加密和解密DTF的分组。为了加强安全和隐私并降低能源使用,私人钥匙可能非常大,例如数千位。 SDN控制平面可以配置每个DTF以实现所需的安全级别,超出现有方案,例如AES,通过使用非常长的键。加密/解密单元还使用新的串行排列单元非常低的硬件成本,这允许FPGA硬件中的卓越安全性和非常高的吞吐量。

著录项

  • 公开/公告号US11019038B2

    专利类型

  • 公开/公告日2021-05-25

    原文格式PDF

  • 申请/专利权人 TED H. SZYMANSKI;

    申请/专利号US201716075402

  • 发明设计人 TED H. SZYMANSKI;

    申请日2017-02-03

  • 分类号H04L29/06;H04L12/863;H04L9/08;H04L29/08;H04L12/937;H04L9/14;H04L12/851;H04L12/873;H04L12/933;H04L12/935;H04L12/715;

  • 国家 US

  • 入库时间 2022-08-24 18:52:36

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号