基于往返延时一致性测量的远程有线多跳网络密钥协商机制OA
Round-Trip Delay Consistency Measurement Based Key Agreement for Remote Wired Multi-Hop Networks
针对远程有线多跳网络场景下物理层密钥协商面临的熵源获取困难与双端测量一致性问题,提出基于延时一致性测量的密钥协商机制.以网络层往返时延(RTT)一致性特征为候选熵源,通过互联网控制报文协议(ICMP)探测获取双端时延测量序列,并利用时延抖动的频域特征表征网络路径响应;结合累积分布函数(CDF)量化、Cascade 信息协调与 2-通用哈希隐私放大生成一致密钥.跨地区远程网络实验结果表明,初始密钥一致率平均达 72.33%,经协调后最终一致率为 100%,生成密钥材料通过美国国家标准与技术研究院(NIST)的随机性测试.网络层时延一致性可作为远程有线多跳网络无条件安全密钥生成的可行熵源.
Conventional key agreement schemes rely on computational hardness assumptions and are vulnerable to future quantum attacks,while wireless physical-layer methods based on channel reciprocity suffer from distance sensitivity and poor adaptability to multi-hop topologies.To address these issues,this paper proposes a remote key agreement mechanism for wired multi-hop networks that exploits the consistency of network-layer round-trip time(RTT)as a candidate entropy source.The legitimate endpoints perform active probing using Internet Control Message Protocol(ICMP)Echo requests and replies,record bidirectional RTT sequences,and extract frequency-domain magnitude spectra of delay jitter to characterize the path response.After weighted moving average(WMA)preprocessing,cumulative distribution function(CDF)-based quantization generates initial bit sequences,followed by Cascade information reconciliation and 2-universal hashing privacy amplification to produce a final consistent key.Experiments on a cross-regional cloud testbed show that the average initial key agreement rate reaches 72.33%,and after reconciliation the final consistency is 100%.The generated keys pass the National Institute of Standards and Technology(NIST)randomness tests,with an average generation rate of about 500 bit/s.Furthermore,path-internal eavesdropping experiments demonstrate that an adversary observing only local link delays achieves bit agreement rates close to random guessing(≤54.4%),confirming the structural asymmetry of bidirectional RTT measurements.A quantitative information-theoretic analysis shows that the scheme can extract about 834 bits of secure key under typical parameters.This work extends the entropy source of unconditionally secure key generation from physical-layer wireless features to network-layer delay characteristics,offering a practical solution for remote terminal key establishment in power communication networks and similar infrastructure scenarios without relying on public-key infrastructure.
祁学豪;刘溪禹;宋宇波;唐旭升;姚启桂
东南大学网络空间安全学院 南京 210096||紫金山实验室 南京 210096东南大学网络空间安全学院 南京 210096东南大学网络空间安全学院 南京 210096||紫金山实验室 南京 210096||新疆战略性矿产资源绿色智能开发与高效利用兵团重点实验室大数据与信息工程学院新疆工业学院 和田 848000东南大学网络空间安全学院 南京 210096||紫金山实验室 南京 210096中国电力科学研究院有限公司 南京 210003
信息技术与安全科学
密钥协商延时测量有线信道远程设备互易性
Key agreementdelay measurementwired channelremote devicesreciprocity
《电工技术学报》 2026 (13)
4469-4488,20
评论