摘要
以太网数据链路安全网关加密链路层以上所有数据,使攻击者即使截取到数据包也不能得到重要信息,对以太局域网的安全保护具有重要意义。本文将对以太网链路安全网关数据帧的SM4加解密、SM3完整性校验等数据处理过程进行研究,针对安全网关数据处理过程中出现的长度超过MTU值的数据帧,提出了一种新的分片重组解决方案,测试结果表明了该方案的可行性。
All the data above the link layer is encrypted by the Ethernet data link security gateway, the attacker cannot get important data, even if the attacker can get the interception of the packet. The Ethernet link security gateway is significance for the protection of Ethernet local area network. In this paper, the encryption and decryption of SM4, integrity verification of SM3 and other data processing procedures are studied, and a new fragment reassembly method is proposed to solve the data frames more than MTU value. The test results show the feasibility of the proposed scheme.
作者
李兆斌
茅方毅
王瑶君
Li Zhaobin Mao Fangyi Wang Yaojun(Beijing Electronic Science and Technology Institute, Beijing 100070, China)
出处
《北京电子科技学院学报》
2016年第2期51-57,共7页
Journal of Beijing Electronic Science And Technology Institute
基金
中央高校基本科研业务费专项资金资助(项目编号:328201538)资助~~
关键词
以太网链路层加解密
完整性校验
分片重组
Ethernet data link encryption and decryption
integrity verification
fragment reassembly