Practical privacy in WDM networks with all-optical layered encryption

Practical privacy in WDM networks with all-optical layered encryption
复制标题

DOI:
10.1109/icc.2017.7996813
复制
发表时间:
2016-10
期刊:
2017 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
Anna Engelmann;A. Jukan
Anna Engelmann;A. Jukan
中科院分区:
其他
文献类型:
--
作者:
Anna Engelmann;A. Jukan

文献摘要

相似文献

与当今基于洋葱路由(Tor)的匿名IP网络相比,在光路由器中,匿名通信形式的隐私可能更快,更难被打破。然而,全光学地实现实际的隐私并不简单,因为它需要在每个匿名化节点中生成密钥以避免长密钥的分发,以及分层加密,两者都以光线路速率进行。由于密码学上强的光学密钥生成和加密组件的不可用,不仅分层加密是一个挑战,而且一般的光学加密也是一个挑战。在本文中,我们解决了光学匿名网络的挑战,第一次从系统的角度来看,并讨论了全光分层加密的实际实施方案。为此,我们提出了一个光学匿名组件实现与国家的最先进的光学XOR逻辑和光学线性反馈移位寄存器(oLFSR)。鉴于LFSR单独是已知的弱密码安全性,由于其线性特性,我们提出了一个实现与并行oLFSR和分析所产生的计算安全性。结果表明,提出的光学匿名组件是有前途的,因为它可以实际实现,以提供一个高的计算安全性,对去匿名(隐私)攻击。
Privacy in form of anonymous communication could be comparably both faster and harder to break in optical routers than in today's anonymous IP networks based on The Onion Routing (Tor). Implementing the practical privacy all-optically, however, is not straightforward, as it requires key generation in each anonymization node to avoid distribution of long keys, and layered encryption, both at the optical line rate. Due to the unavailability of cryptographically strong optical key generation and encryption components, not only a layered encryption is a challenge, but an optical encryption in general. In this paper, we address the challenges of optical anonymous networking for the first time from the system's perspective, and discuss options for practical implementation of all-optical layered encryption. To this end, we propose an optical anonymization component realized with the state-of-the-art optical XOR logic and optical Linear Feedback Shift Registers (oLFSRs). Given that LFSR alone is known for its weak cryptographic security due to its linear properties, we propose an implementation with parallel oLFSRs and analyze the resulting computational security. The results show that proposed optical anonymization component is promising as it can be practically realized to provide a high computational security against deanonymization (privacy) attack.