摘要
在公开的计算机网络中采用洋葱路由能提供隐蔽网络连接,实现隐藏网络结构和通信双方地址等关键信息,对通信的数据进行安全保护,然而洋葱路由技术对数据包经过的中继节点需要进行层层加密封装,从而降低路由转发效率,增大资源消耗。针对此问题,提出了一种改进的隐匿网络结构方案,使得数据传输路径随机化。数据从发送端发送,发送端要把发送的数据提前分成若干部分,每部分通过一系列的代理且沿一条不可预测的路径发送信息,直到目的地址。对方案的安全性分析以及实验结果表明:该方案具有隐匿网络结构、防止攻击者流量分析及保证数据的保密性的特点,有效地解决了路由转发效率低下的问题。
Onion Routing in open computer networks can offer anonymous network connections and hide the network structure and key information of the communication, thus to hide communication over Internet. However, Onion Routing needs to encrypt and encapsulate packets layer by layer on each node, thereby reducing forwarding efficiency and increasing resource consumption. To solve this problem, a new scheme based on Onion Routing is proposed. The new scheme randomizes the data transmission path. The sender divides the data into several parts before sending, and each part is forwarded through a series of agents and along an unpredictable path to the destination address. Analysis and experimental results show that the scheme can hide the network structure, prevent flow analysis, ensure data confidentiality, and effectively improves the routing efficiency.
出处
《信息工程大学学报》
2016年第6期719-723,共5页
Journal of Information Engineering University
基金
上海市科研计划资助项目(14DZ1105300
13DZ1108800)
关键词
网络安全
洋葱路由
保密性
network security
Onion Routing
confidentiality