节点文献

正交频分复用无源光网络物理层安全防护技术研究

Physical Layer Security Protection Technologies of Orthogonal Frequency Division Multiplexing Passive Optical Network

【作者】 李珊珊;

【导师】 刘德明; 程孟凡;

【作者基本信息】 华中科技大学 , 电子科学与技术, 2020, 博士

【摘要】 当今世界,信息已成为至关重要的战略资源。日益增长的带宽需求对现有的光网络带来挑战,保障网络安全成为保障国家安全的重要任务。正交频分复用无源光网络(OFDM-PON)因其频谱利用率高、抗色散能力强、资源分配灵活和实现成本低等优势,成为下一代光接入网的优势候选之一。然而,无源光网络的点对多点拓扑结构和下行信号的广播通信方式,使得接入网物理层面临被入侵、窃听和冒充等多种安全威胁。在物理层实施高灵活性、低代价的安全防护措施能够实现对网络信息的全方位保障。研究OFDM-PON物理层安全防护技术,对于推动网络跨层安全机制的协同,实现大容量的安全光接入网系统具有重要意义。论文主要研究成果如下:(1)针对算法安全性与计算复杂度相互制约的问题,提出了基于上下行明文互扰机制的定点数字混沌加密算法。在低精度定点算法约束下,有效改善了数字混沌系统的动力学特性退化效应。设计了对混沌序列进行动态非线性变换的魔方算法,扩大了密钥空间。在计算精度为14比特的定点算法下实现了密钥空间为256×(256!)256≈~10129791的OFDM-PON物理层数据防护机制。(2)针对密钥分发的安全性和信道资源开销问题,提出了基于OFDM混沌导频信号冗余的密钥隐匿分发技术。在不增加额外开销、不影响传输性能的前提下,利用所构造的混沌导频信息的冗余性实现了密钥的安全隐匿传输。实验验证了速率为28.4Mb/s的密钥分发与速率为7.64 Gb/s的16-QAM OFDM数据安全传输协同防护机制。(3)针对传统身份认证协议复杂的问题,提出了基于小波变换和卷积神经网络的硬件指纹识别身份认证技术。将ONU设备容差对传输信号的影响作为硬件指纹,将OFDM导频信号作为指纹载体,在OLT端实现对ONU硬件身份认证;实验验证合法ONU的身份识别准确率可达97.41%,非法ONU的识别准确率可达100%,能够抵御物理层非授权接入、身份欺骗攻击等安全威胁。

【Abstract】 Nowadays,information has become a crucial strategic resource.The increasing demand for bandwidth brings challenges to the existing optical network,and the protection of network security becomes an important task of national security.The orthogonal frequency division multiplexing passive optical network(OFDM-PON)has become one of the outstanding candidates to meet requirements of the next generation optical access network due to its high spectral efficiency,robustness to fiber dispersion,flexibility of resource allocation,and low implementation cost.However,due to the point-to-multipoint topology of passive optical network(PON)and the broadcast communication mode of downlink signal,the physical layer of access network is vulnerable to intrusion,eavesdropping and spoofing attack.Security measures in the physical layer with high flexibility and low-cost can strengthen the all-round protection of network information.The research of OFDM-PON security technology in the physical layer is of great significance,which can promote the cooperation of cross layer security mechanism and realize the high-capacity secure optical access network system.The main research results of this thesis are as follows:(1)Aiming at the problem of mutual restriction between algorithm security and computational complexity,a digital chaos encryption algorithm based on uplink and downlink plaintext mutual interference mechanism is proposed.Under the constraint of low precision fixed-point algorithm,the dynamical degradation effect of digital chaotic system is effectively improved.A Rubik’s cube algorithm for dynamic nonlinear transformation of chaotic sequences is designed to expand the key space.The physical layer data protection mechanism for OFDM-PON with a key space of 256×(256!)256≈~10129791 is implemented when the calculation precision of the fixed-point algorithm is 14 bits.(2)Aiming at the security of key distribution and the cost of channel resources,a technology of key hide distribution based on chaotic pilot signal is proposed.Under the premise of no additional overhead and no impact on the transmission performance,the security of secret key transmission is realized by using the redundancy of the constructed chaotic pilot information.The cooperative protection mechanism of key distribution and16-QAM OFDM data security transmission is verified by experiments,in which key distribution rate is 28.4 Mb/s and data transmission rate is 7.64 Gb/s.(3)Aiming at the complexity of traditional identity authentication protocols,a hardware fingerprint identification technology based on wavelet transform and convolutional neural network is proposed.The impact of ONU device tolerance on transmission signal is taken as hardware fingerprint,and OFDM pilot signal is taken as fingerprint carrier to realize ONU hardware identity authentication at OLT.Experimental results show that the identification accuracy of legal ONU can reach 97.41%,and that of illegal ONU can reach 100%,which indicates that security threats such as unauthorized access and spoofing attack in the physical layer can be resisted.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络