基于真实源地址验证的轻量共识机制
CSTR:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP393

基金项目:

国家自然科学基金(62132011)


Lightweight Consensus Mechanism Based on Source Address Validation
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    近年来, 许多研究提出利用共识机制增强网络层安全性. 然而, 现有共识机制存在密钥维护数量多、信任关系传递不灵活和节点身份验证开销大等局限, 难以满足网络层功能的性能需求. 为解决这些问题, 提出一种基于真实源地址验证技术的轻量共识框架. 该框架在多个层次上优化共识效率: 首先, 针对同一地址域内的共识节点, 该框架利用真实地址作为身份识别标志, 通过域内节点共享同一密钥的方式实现密钥聚合, 从而大幅降低所需维护的密钥数量; 其次, 在地址域的粒度上, 该框架构建以真实地址为信任基础的网络信任联盟, 基于前缀树聚合可信地址域, 从而在实现灵活信任传递的同时, 进一步降低所需维护的密钥数量; 最后, 在节点层面, 针对传统共识节点身份验证开销大的问题, 该框架设计基于真实地址和对称密钥的分步验证机制, 从而有效降低共识开销, 实现共识过程轻量化. 仿真实验证明, 所提出的轻量共识框架与基于ECDSA身份验证的共识机制相比, 平均可提升70%共识吞吐量并降低40%共识计算开销, 显著提升了共识效率.

    Abstract:

    In recent years, many studies have proposed using consensus mechanisms to enhance network layer security. However, existing consensus mechanisms have limitations, such as heavy key maintenance, inflexible trust expansion, and high authentication overhead. To address these issues, this study proposes a lightweight consensus framework based on source address validation. The framework optimizes consensus efficiency at multiple levels: First, among consensus nodes within the same domain, the framework uses authentic IP addresses as identities and achieves key aggregation by sharing the same key among nodes within the domain, thus efficiently reducing the number of keys that need to be maintained. Second, at the domain level, the framework constructs a trusted network alliance based on trust derived from authentic IP addresses and aggregates trusted domains through a prefix tree, thus further reducing the number of keys to maintain while enabling flexible trust expansion. Finally, at the node level, to address the issue of high authentication overhead, the framework designs a two-step authentication mechanism based on authentic IP addresses and symmetric keys, effectively reducing overhead and enabling a lightweight consensus process. Simulation experiments show that the proposed framework can improve consensus throughput by 70% and reduce consensus latency by 40% on average, compared to the consensus mechanism based on ECDSA authentication, significantly improving consensus efficiency.

    参考文献
    相似文献
    引证文献
引用本文

徐易,陈熠豪,王晓亮,徐恪,李琦.基于真实源地址验证的轻量共识机制.软件学报,,():1-16

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-12-24
  • 最后修改日期:2025-02-06
  • 录用日期:
  • 在线发布日期: 2025-11-05
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号