An Adaptive Secure Network Coding Method Based on Null Space

Through the adaptive secure network encoding method, the zero-space characteristic optimization detection strategy is used to solve the problem of multiple malicious nodes conspiring to attack, and dynamic verification under different network security levels is achieved, and data transmission efficiency and security are improved.

CN115941284BActive Publication Date: 2025-07-11NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211412630.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-11
Publication Date
2025-07-11
Estimated Expiration
2042-11-11

AI Technical Summary

Technical Problem

The existing zero-space-based secure network coding scheme cannot effectively resist conspired pollution attacks by multiple malicious nodes, and under different levels of network security, the verification mechanism cannot be dynamically adjusted, resulting in waste of resources and inefficiency.

Method used

Adaptive secure network encoding method is adopted, and the encoded data packets and verification vectors are generated by the source node, the intermediate nodes perform legality verification, and when necessary, the upstream nodes are notified for batch verification, and the sink nodes perform final decoding, using the zero-space characteristics to optimize the detection strategy to reduce calculation overhead.

Benefits of technology

It improves the security of network encoding and data transmission efficiency, can resist conspiracy of multiple malicious nodes, reduce resource consumption, maintain low computing complexity while improving verification efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941284B_ABST
    Figure CN115941284B_ABST
Patent Text Reader

Abstract

The present invention discloses an adaptive secure network coding method based on the null space, including: system parameter initialization, generating transmission data packets and verification vectors, intermediate node verification and re-encoding, and destination node decoding. The security of the adaptive secure network coding method based on the null space is achieved by the characteristics of the null space and the linear space of the data vectors, and the optimization of the detection strategy and the reduction of overhead are realized through the adaptive detection mechanism. The present invention can overcome the contamination problem in the classical null space network coding method that cannot resist the collusion of multiple malicious nodes, and dynamically change the detection strategy according to the network characteristics, so as to achieve the purpose of reducing the computational overhead, improving the verification efficiency, and reducing the consumption of network resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network coding security, and relates to an adaptive secure network coding method based on the null space. Background Art

[0002] Network coding is a new way of transmitting data. That is, intermediate nodes in the network not only undertake the routing function, but also perform coding and forwarding at the same time. Finally, the destination decodes the received data packets to obtain the data packets sent by the source. The original purpose of network coding was to improve data throughput and can reach the theoretical upper limit of multicast network traffic. Network coding can be divided into deterministic network coding and random linear network coding according to the selection method of coding coefficients. Among them, random linear network coding does not need to know the network topology in advance, and the coding coefficients participating in network coding are randomly selected from a pre-set finite field, and can still ensure a high decoding probability in the case of unknown network topology.

[0003] Due to the characteristics of network coding, as long as there are a small number of contaminated data packets in the network, it will cause great damage to the performance and security of the entire network. Therefore, in the actual use of network coding, ensuring that there is no contamination attack in the network is the primary premise. So a large number of secure network coding schemes have been proposed. According to different anti-contamination ideas, they can be roughly divided into two parts: information theory-based schemes and cryptography-based schemes. Among the cryptography-based schemes, the null space-based anti-contamination scheme has become one of the main research directions of secure network coding technology due to its efficient contaminated information filtering and low computational overhead.

[0004] The traditional null space-based secure network coding scheme is that the source node forms a linear space by spanning the matrix composed of data vectors to be transmitted, calculates a set of bases of the null space by solving a system of linear equations, and the vector generated by the linear combination of this set of bases is a null vector of the null space, while the vector generated by the linear combination of the source node is the data vector. The null vector is transmitted through the network to the intermediate node. At the same time, the intermediate node judges whether the data vector is a legal data vector through a formula according to the received data vector.

[0005] However, the above verification method cannot completely prove whether the data vector is legal. Because if there are multiple malicious nodes colluding in the transmission network, that is, the downstream malicious node collects enough null vectors for verification, the upstream malicious node can easily calculate the contaminated vector that satisfies the inner product with the null vector being 0. Because the null space generated by the matrix composed of data vectors is relatively fixed, if contaminated data packets are generated and encoded and forwarded, they cannot be detected. Thus, the security of the null space-based secure network coding scheme is damaged.

[0006] In reality, the security levels of networks vary. According to many network detection mechanisms for anti-pollution attacks proposed in previous studies, even when intermediate nodes are not under pollution attacks, a large amount of network resources are spent on detecting the legality of data packets, and the verification mechanism cannot be dynamically adjusted according to the network situation. Summary of the Invention

[0007] Objective: To overcome the deficiencies in the prior art, the present invention provides an adaptive secure network coding method based on the null space.

[0008] In this application, on the premise of ensuring security, especially resisting collusion attacks, the verification mechanism of intermediate nodes can be dynamically adjusted according to the security level of the network, reducing resource waste and improving data transmission efficiency; at the same time, when a pollution attack is launched by multiple malicious nodes in collusion, this solution can still verify the legality of data packets.

[0009] Technical Solution: To solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0010] In a first aspect, an adaptive secure network coding method based on the null space is provided, including:

[0011] Adopt a network coding system; the system includes a source node S, intermediate nodes V i , and a sink node R i ; including:

[0012] Step S1: Use the identity matrix to expand the data vector matrix P to be transmitted to obtain an expanded data vector matrix X, and perform block processing on the expanded data vector matrix X to obtain several data vector sets each containing data vectors.

[0013] Step S2: The source node S generates encoded data packets and verification vectors:

[0014] From the initial time T0, every time the source node passes unit time, one more data vector set is added to participate in the encoding and forwarding operation of the source. At time , where i is the number of times of passing unit time, which is a natural number, the data vector sets participating in the encoded transmission in the source node where is the number of data vectors in the data vector matrix P and the expanded data vector matrix X;

[0015] At time the source node S uses the data vector set X p to generate encoded data packets and forward them to the first intermediate node;

[0016] Forward the data packet by coding every times, generate and send a verification vector once At time point At the moment, the source node S uses the data vector set X q To generate a verification vector And attach the sending time T now Of the verification vector And send it to the first intermediate node; wherein the data packet includes the data vector generated by coding And the hop count L information of the corresponding data vector;

[0017] Step S3: The intermediate node receives the data packet forwarded by the upstream node and verifies the legality of the received data packet according to the verification vector;

[0018] Step S4: The intermediate node re-encodes the data packet for the verified data vector and sends it to the downstream node;

[0019] Step S5: The destination node R i Receives the data packet sent by the adjacent intermediate node and verifies the legality of the received data packet, and decodes the data packet passing the legality verification to obtain the data vector matrix P.

[0020] In some embodiments, in step S1, the data vector matrix P to be transmitted is expanded using the identity matrix to obtain the expanded data vector matrix X, including:

[0021] The data vector matrix P consists of m linearly independent n-dimensional data vectors of the same generation,

[0022] Add an n×n identity matrix for recording coding coefficients before the data vector matrix P to expand and obtain the expanded data vector matrix X;

[0023] In step S1, the expanded data vector matrix X is block-processed to obtain several groups of data vector sets containing Data vectors, including:

[0024] The block rule is: Is a preset positive integer, and the expanded data vector matrix X is divided into several groups of data vector sets, where each group of data vector sets includes Data vectors. If there are finally insufficient data vector numbers They are divided into one group.

[0025] In some embodiments, in step S2, the source node S uses the data vector set X p To generate the encoded data packet, including:

[0026] The data vector generated by encoding is:

[0027]

[0028] where c i is the encoding coefficient, randomly selected from the preset finite field F q ; is the data vector in the data vector set X p ;

[0029] Set a hop count L for each data vector generated by encoding. The initial value of the hop count L is set to 0 and attached to the tail of the data vector generated by encoding to form a data packet.

[0030] In some embodiments, in step S2, the source node S uses the data vector set X q to generate a verification vector including:

[0031] Using the random vector to fill the data vector set into a set C of m vectors q :

[0032]

[0033] The elements of the random vector are randomly obtained from the preset finite field F q , and the random vector is linearly independent of the data vector set ;

[0034] Solve the system of equations by Gaussian elimination to find the matrix composed of linearly independent vectors that satisfy the equation Use the matrix to span the linear space of C q Use the linear equation to obtain the null space Arbitrarily select a set of bases in the null space for linear combination to generate the verification vector

[0035] In some embodiments, in steps S3 and S5, the legitimacy verification of the received data packet includes:

[0036] (S31) The node obtains the data packet carrying the hop count information, and attaches the created flag z and the T receive parameter information to the head of the data vector in the received data packet to obtain the processed data packet; where flag z ​Indicates the verification status of the data vector. Set the value of flag z to 0, indicating that it has not been verified yet; T receive represents the current system time received by node v;

[0037] (S32) Judge the working status of the node;

[0038] In response to the parameter T = 0 indicating the working status of the node, it means the node is in a normal working state. Judge whether the number of hops L passed by the processed data packet after the last security verification exceeds the preset maximum number of hops L max , in response to L exceeding L max , then wait for the next security verification. If it does not exceed, skip the security verification and wait for coding and forwarding;

[0039] In response to T > 0, it means the node is in an abnormal working state. All data packets received by the node in this state need to pass security verification before continuing to be transmitted; the initial value of the parameter T is 0;

[0040] (S33) After the node receives the verification vector, only keep a series of the most recently sent verification vectors, and form these latest verification vectors into a verification vector matrix B v , the intermediate node v will send a verification vector that is a random linear combination of the vectors in the verification vector matrix B v and transmit it to the downstream node through the network link;

[0041] Use the verification vector matrix B v to verify those data vectors whose reception time is not later than the transmission time of B v and have not been verified, that is, flag z = 0, T receive ≤ T now - Δ; Δ is the maximum time difference between the node and the source node, and the network has been synchronized; B s is the matrix obtained by deleting the system time parameter from B v ; Judge whether the data vector can pass the verification: In response to being established, the data vector passes the verification; otherwise, the data vector cannot pass the verification and is regarded as a contaminated data packet and discarded.

[0042] Step S3 also includes: (S34) For the data vector that passes the verification, set the value of flag z to 1, indicating that it has passed the security verification, wait for coding and forwarding, and set the number of hops L in the data packet to 0. At this time, if the state parameter T of the node > 0, then subtract 1 from the value; if the state parameter T = 0, then keep it unchanged;

[0043] For the data vector that fails to pass the verification, compare the state parameter T of the intermediate node with the preset maximum state parameter T max as follows:

[0044] When the state parameter T of the intermediate node is less than the preset maximum state parameter T max , increase the value of the state parameter T of this node by L min where L is the minimum number of hops in the pollution data packets detected in a certain time period, and γ and λ are preset parameters dynamically adjusted according to the needs of network security. Discard the data vector that fails to pass the verification as a pollution data packet;

[0045] When the state parameter T of the intermediate node ≥ T max , send a reminder notification to the upstream node through the security channel arranged in advance in the network system, and perform batch verification on the data packets received by the upstream node. If the batch verification fails, the state parameter T of the upstream node increases and locate the pollution data packet through information search technology, and discard the pollution data packet.

[0046] In some embodiments, step S4 includes:

[0047] (S41) Whenever there is a new verified data vector, the intermediate node v performs a random linear combination on all the verified data vectors to generate a new data packet and send it to the downstream node. Suppose there are l data vectors The encoding process is: where η i is a random element in the preset finite field F q ;

[0048] (S42) Update the hop count L of the new data packet to:

[0049] In some embodiments, step S5 includes:

[0050] (S51) When the data packet reaches the destination node, verify the legality of the data packet;

[0051] (S52) When the destination node R i receives m linearly independent data vectors that pass the data packet legality verification, decode the data vector matrix P composed of the original data vectors according to the inverse matrix of its identity matrix.

[0052] In a second aspect, the present invention provides an adaptive secure network coding device based on the null space, including a processor and a storage medium;

[0053] The storage medium is used to store instructions;

[0054] The processor is used to operate according to the instruction to execute the steps of the method according to the first aspect.

[0055] In a third aspect, the present invention provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method according to the first aspect are implemented.

[0056] Beneficial effects: The adaptive secure network coding method based on the null space provided by the present invention has the following advantages: The security of the adaptive secure network coding method based on the null space is realized by the characteristics of the null space and the linear space of the data vector. The optimization of the detection strategy and the reduction of overhead are realized through the adaptive detection mechanism. The present invention can overcome the pollution problem that the classical null space network coding method cannot resist the collusion of multiple malicious nodes, and dynamically change the detection strategy according to the network characteristics, so as to reduce the computational overhead, improve the verification efficiency, and reduce the consumption of network resources. On the basis of maintaining the advantage of low computational complexity of intermediate nodes in the classical scheme, it can also resist the pollution attack of the collusion of multiple malicious nodes, and introduce an adaptive detection mechanism to further reduce the network information transmission overhead. The present invention has the advantages of strong security and high computational efficiency, and can be popularized and applied in secure network coding. Description of the Drawings

[0057] Figure 1 It is a single-source multicast network model diagram according to an embodiment of the present invention;

[0058] Figure 2 It is a flowchart of the adaptive secure network coding method based on the null space of the system according to an embodiment of the present invention. Detailed Embodiments

[0059] The present invention will be further described below with reference to the drawings and embodiments. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention, and cannot be used to limit the protection scope of the present invention.

[0060] In the description of the present invention, the meaning of several is more than one, the meaning of multiple is more than two, greater than, less than, exceeding, etc. are understood as not including the present number, and above, below, within, etc. are understood as including the present number. If the first and second are described only for the purpose of distinguishing technical features, they cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or implicitly indicating the sequence relationship of the indicated technical features.

[0061] In the description of the present invention, the descriptions referring to terms such as "one embodiment", "some embodiments", "schematic embodiments", "examples", "specific examples", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0062] Embodiment 1

[0063] The system model of this embodiment is as Figure 1 shown. The system consists of a single-source multicast network model and several mobile devices, and one of the mobile devices is set as the source node; in the solution of this embodiment, the network has one source node S, multiple destination nodes R i and multiple intermediate nodes V i ; at the same time, the network will pre-specify a finite field F q for selecting coding coefficients; if there are too many data vectors to be transmitted, the data vectors can also be divided into generations, and only the data packets in the same generation can be encoded and forwarded to generate new data packets; the source node S uses the method of random linear network coding to generate data packets and send them to all destination nodes, and the intermediate nodes V i similarly; in the present invention, it is default that the source node is a trusted node, and the destination nodes and intermediate nodes are not trusted nodes.

[0064] An adaptive secure network coding method based on the null space, comprising:

[0065] Adopting a network coding system; the system includes a source node S, intermediate nodes V i , destination nodes R i ; including:

[0066] Step S1: Expand the data vector matrix P to be transmitted by using the identity matrix to obtain an extended data vector matrix X, and perform block processing on the extended data vector matrix X to obtain several data vector sets each containing data vectors;

[0067] Step S2: The source node S generates encoded data packets and verification vectors:

[0068] From the initial moment T0, every time the source node passes unit time, it adds a set of data vector sets to participate in the encoding and forwarding operation of the source. At the moment , where i is the number of passes of The number of times per unit time, which is a natural number, is the set of data vector involved in encoding and transmission in the source node wherein m is the number of data vectors in the data vector matrix P and the extended data vector matrix X;

[0069] At time The source node S uses the set of data vectors X p to generate an encoded data packet and forward it to the first intermediate node;

[0070] Every interval of times of encoding and forwarding data packets, a verification vector is generated and sent once At the time point At the moment, the source node S uses the set of data vectors X q to generate a verification vector and attach the sending time T now of the verification vector and send it to the first intermediate node; wherein the data packet includes the data vector generated by encoding and the hop count L information of the corresponding data vector;

[0071] Step S3: The intermediate node receives the data packet forwarded by the upstream node and verifies the legality of the received data packet according to the verification vector;

[0072] Step S4: The intermediate node re-encodes the data packet for the data vector that passes the verification and sends it to the downstream node;

[0073] Step S5: The destination node R i receives the data packet sent by the adjacent intermediate node and verifies the legality of the received data packet, and decodes the data packet that passes the legality verification to obtain the data vector matrix P.

[0074] In step S1, the data vector matrix P to be transmitted is extended using the identity matrix to obtain the extended data vector matrix X, including:

[0075] The data vector matrix P is composed of m linearly independent n-dimensional data vectors of the same generation,

[0076] An n×n identity matrix for recording encoding coefficients is added before the data vector matrix P to obtain the extended data vector matrix X by extension;

[0077] In step S1, the extended data vector matrix X is block-processed to obtain several sets of data vector sets containing data vectors, including:

[0078] The block rule is: Let \(n\) be a preset positive integer. The extended data vector matrix \(X\) is divided into several groups of data vector sets, where each group of data vector sets includes data vectors. If the number of the last data vectors is less than , they are grouped into one group.

[0079] In step S2, the source node \(S\) uses the data vector set \(X\) p to generate encoded data packets, including:

[0080] The encoded data vector is:

[0081]

[0082] where \(c\) i is an encoding coefficient randomly selected from a preset finite field \(F\) q ; is a data vector in the data vector set \(X\) p ;

[0083] Set a hop count \(L\) for each encoded data vector. The initial value of the hop count \(L\) is set to 0 and is attached to the tail of the encoded data vector to form a data packet.

[0084] In step S2, the source node \(S\) uses the data vector set \(X\) q to generate a verification vector including:

[0085] Using the random vector to fill the data vector set into a set \(C\) of \(m\) vectors q :

[0086]

[0087] The elements of the random vector are randomly obtained from a preset finite field \(F\) q , and the random vector is linearly independent of the data vector set ;

[0088] Solve the system of equations by Gaussian elimination to obtain a matrix composed of linearly independent vectors that satisfy the equation Use the matrix to span the linear space q of \(C\) Use a linear equation to obtain the null space Arbitrarily select a set of bases in the null space to perform a linear combination to generate the verification vector

[0089] In steps S3 and S5, the legal verification of the received data packet includes:

[0090] (S31) The node obtains the data packet carrying the hop count information, and attaches the created flag z and T receive parameter information to the head of the data vector in the received data packet to obtain the processed data packet; where flag z represents the verification status of the data vector, and sets the value of flag z to 0, indicating that it has not been verified yet; T receive represents the current system time received by node v;

[0091] (S32) Determine the working status of the node;

[0092] In response to the parameter T = 0 indicating the working status of the node, it means that the node is in a normal working state. Determine whether the number of hops L passed by the processed data packet since the last security verification exceeds the preset maximum number of hops L max , and in response to L exceeding L max , wait for the next security verification. If it does not exceed, skip the security verification and wait for encoding and forwarding;

[0093] In response to T > 0, it means that the node is in an abnormal working state, and all data packets received by the node in this state need to pass security verification before continuing to be transmitted; the initial value of parameter T is 0;

[0094] (S33) After the node receives the verification vectors, only retain the series of verification vectors sent most recently, and form these latest verification vectors into a verification vector matrix B v , in order to enable downstream nodes to quickly obtain the verification vectors, the intermediate node v will send the random linear combination of the vectors in the verification vector matrix B v , and the result is transmitted through the network link;

[0095] Use the verification vector matrix B v to verify those data vectors whose reception time is not later than the transmission time of B v , and have not been verified, that is, flag z = 0, T receive ≤ T now -Δ; Δ is the maximum time difference between the node and the source node, and the network has achieved synchronization; B s is the matrix obtained by deleting the system time parameter from B v ; Determine whether the data vector can pass the verification: in response to being established, the data vector passes the verification; otherwise, the data vector cannot pass the verification and is regarded as a contaminated data packet and discarded.

[0096] Step S3 further includes: (S34) Using the verified data vector, set the flag z value to 1, indicating that the security verification has passed, waiting for encoding and forwarding, and set the hop count L in the data packet to 0. At this time, if the state parameter T of this node > 0, then subtract 1 from the value; if the state parameter T = 0, then keep it unchanged;

[0097] For the data vector that fails the verification, compare the state parameter T of the intermediate node with the preset maximum state parameter T max as follows:

[0098] When the state parameter T of the intermediate node is less than the preset maximum state parameter T max , increase the value of the state parameter T of this node by L min which is the minimum hop count detected as a contaminated data packet in a certain time period, and γ, λ are preset parameters dynamically adjusted according to the needs of network security. Discard the data vector that fails the verification as a contaminated data packet;

[0099] When the state parameter T of the intermediate node ≥ T max , send a reminder notification to the upstream node through the security channel pre-arranged in the network system, and perform batch verification on the data packets received by the upstream node. If the batch verification fails, the state parameter T of the upstream node increases and locate the contaminated data packet through information search techniques (binary tree retrieval, dichotomy) and discard the contaminated data packet.

[0100] The adaptive secure network coding method based on the null space provided in this embodiment includes the following steps:

[0101] Step 1: System parameter initialization;

[0102] The specific implementation includes the following sub-steps:

[0103] Step 1.1: Perform a generation-based partitioning of the data vectors. Only the data vectors in the same generation can be encoded and forwarded to generate new data packets; Assume that the data vector matrix P of each generation consists of m linearly independent n-dimensional data vectors; To enable the destination to successfully decode, the source needs to add an n×n identity matrix before the data vector matrix to record the encoding coefficients. The data vector matrix X after adding the identity matrix is obtained by expanding the data vector matrix P;

[0104] Step 1.2: Before the source node encodes and generates data packets for transmission, perform a block processing on the data vector matrix X. The block rule is: is an integer preset in the network system. Divide the data vector matrix X into several groups, where each group includes A set of vector sets of data vectors, and finally the number of vectors is insufficient are grouped into one group; at the same time, a finite field F is selected for the network q to select the coding coefficients;

[0105] Step 1.3: Set the unit time for data packet transmission between adjacent nodes in the network to μ, and at the same time set the maximum transmission time of data packets in the network to M unit times, and the time when the source starts sending data packets is T0;

[0106] Step 1.4: Starting from the time T0 when the source starts encoding and sending data packets, every time a unit time passes, a set of data vector sets is added to participate in the encoding and forwarding operation of the source. At system time i is the number of times of passing a unit time, and the data vector matrix participating in encoding and transmission in the source

[0107] Step 2: The source node S generates encoded data packets and verification vectors, as Figure 2 shown;

[0108] The specific implementation of Step 2 includes the following sub-steps:

[0109] Step 2.1: The data vectors encoded and generated by the source node are as shown in the formula c i is the coding coefficient, randomly selected from the preset finite field F q . A hop count parameter L is set for each data vector. The initial value of the hop count L is set to 0 and is attached to the tail of the data vector to form a data packet, and the hop count L does not participate in the coding combination operation of the network;

[0110] Step 2.2: Starting from the source startup, every times of encoding and forwarding data packets, a verification vector is generated and sent once Suppose at the time point t, at this time the source uses the vector set to participate in encoding and forwarding to generate the data packet to be transmitted. In order to obtain the verification vector first generate the null space of the verification vector By filling random vectors, the vector set is filled to a set of m vectors, denoted as: Random vector The elements of are randomly obtained from the finite field F q . The random vector only needs to be linearly independent of the vector set ; Then C qForm a linear space Calculate the null space using linear equations Then solve the system of equations by Gaussian elimination Find the matrix composed of linearly independent vectors that satisfy the equation (the number of vectors, i.e., the dimension of the null space, can be obtained from the rank-nullity theorem); the linear combination of these vectors is the verification vector used for verification The source node sends the verification vector When doing so, first record the current system time T now , and append this time information to the tail of the verification vector; after receiving the verification vector, the intermediate node v will only retain a series of the most recently sent verification vectors, and form a matrix B with these latest verification vectors v , in order to enable downstream nodes to quickly obtain the verification vector, the intermediate node v will send the random linear combination of the vectors in matrix B v , and the result is transmitted through the network link

[0111] Step 3: Intermediate node V i Verify the legality of the data packet

[0112] The specific implementation of Step 3 includes the following sub-steps

[0113] Step 3.1: After obtaining the data packet carrying the hop count information, the intermediate node v will process it: create two parameters flag z and T receive , and append the parameter information to the head of the received data vector; where flag z represents the verification status of the data vector, and T receive represents the current system time received by node v; at the same time, set the value of flag z to 0, indicating that it has not been verified yet

[0114] Step 3.2: Each node has a parameter T representing the working status of the node. If T = 0, it means the node is in a normal working state. At this time, it will first judge the processed data packet. Whether the number of hops passed since the last security verification exceeds L max . If it exceeds, wait for the next security verification. If it does not exceed, skip the security verification and wait for coding and forwarding; at the same time, if T > 0, then all data packets received by the node in this state need to pass the security verification before continuing to be transmitted; the initial value of the parameter T is 0

[0115] Step 3.3: Use B v to verify those data packets whose reception time is not later than the transmission time of B v , and have not been verified, that is, flag z = 0, T receive ≤Tnow - Those data vectors of Δ; Δ is the maximum time difference between the intermediate node v and the source node, and the network has achieved synchronization; the intermediate node v can verify whether the following formula holds: where B s is the matrix obtained by deleting the system time parameter from B v ;

[0116] Step 3.4: Through the verified data vectors, the flag z value can be set to 1, indicating that the security verification has passed, waiting for encoding and forwarding, and the hop count L in the data packet is set to 0. At this time, if the status parameter T of this node > 0, the value is decremented by 1; if the status parameter T = 0, it remains unchanged; the unverified data vectors are regarded as contaminated data packets and will be discarded, and at the same time, the value of the status parameter T of this node is increased L min is the minimum hop count detected as a contaminated data packet in a certain time period; when the status parameter T of the intermediate node > T max , a reminder notification will be sent to the upstream node through the pre - arranged security channel in the network system to batch - verify the data packets it receives. If the batch verification fails, the status parameter T of the upstream node is increased and the contaminated data packet is located through information search technology (such as binary tree retrieval, dichotomy, etc.) and discarded.

[0117] Step 4: The intermediate node re - encodes the data packet;

[0118] The specific implementation of Step 4 includes the following sub - steps:

[0119] (S41) Whenever there is a new verified data vector, the intermediate node v performs a random linear combination on all verified data vectors to generate a new data packet and sends it to the downstream node; assume there are l data vectors The encoding process is: where η i is a random element in the preset finite field F q ;

[0120] (S42) The hop count L of the new data packet is updated to:

[0121] Step 5: The destination node R i receives and decodes the data packet

[0122] The specific implementation of Step 5 includes the following sub - steps:

[0123] (S51) When the data packet is transmitted to the destination node, the same method as above is used to verify the legality of the data packet;

[0124] (S52) When the destination node R i receives m linearly independent data vectors that pass the data packet legality verification, it decodes the data vector matrix P composed of the original data vectors according to the inverse matrix of its identity matrix.

[0125] For the fairness of comparing the two schemes, the overhead savings brought by the adaptive mechanism are not discussed here for the time being.

[0126] As can be seen from Table 1, under the same network conditions, the solution of the present invention not only maintains the low computational overhead of the classical null space solution, but also further optimizes the overhead of data packet transmission;

[0127] Table 1 Comparison of Computational Overheads of Secure Network Coding

[0128]

[0129] As can be seen from Table 2, under the same network conditions, on the basis of maintaining the same intermediate computational intensity, the solution of the present invention can also resist the collusion attacks of multiple malicious nodes;

[0130] Table 2 Comparison of the Anti-Pollution Capabilities of the Solutions

[0131]

[0132] Embodiment 2

[0133] In a second aspect, the present embodiment provides an adaptive secure network coding device based on the null space, including a processor and a storage medium;

[0134] The storage medium is used to store instructions;

[0135] The processor is used to operate according to the instructions to execute the steps of the method according to Embodiment 1.

[0136] Embodiment 3

[0137] In a third aspect, the present embodiment provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method according to Embodiment 1 are implemented.

[0138] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0139] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0140] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0141] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0142] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. An adaptive secure network coding method based on the null space, characterized in that, Adopt a network coding system; The system includes a source node, intermediate nodes, and a sink node; Including: Step S1: The data vector matrix P to be transmitted is extended using the identity matrix to obtain an extended data vector matrix X, and the extended data vector matrix X is block-processed to obtain several data vector sets each containing data vectors; Step S2: The source node S generates encoded data packets and verification vectors: From the initial time T0, every time the source node passes through a unit of time, a set of data vector sets is added to participate in the encoding and forwarding operation of the source. At the time where i is the number of times passing through a unit of time, which is a natural number. The set of data vector sets participating in the encoding and transmission in the source node where m is the number of data vectors in the data vector matrix P and the extended data vector matrix X; At time The source node S uses the data vector set X p to generate an encoded data packet and forward it to the first intermediate node; Forward the data packet by coding every times, generate and send a verification vector once At the time point moment, the source node S uses the data vector set X q to generate a verification vector and send the verification vector now with the attached transmission time T to the first intermediate node; wherein the data packet includes the data vector generated by coding and the hop count L information of the corresponding data vector; Step S3: The intermediate node receives the data packets forwarded by the upstream node and performs a legality verification on the received data packets according to the verification vectors; Step S4: The intermediate node re-encodes the data packets that pass the verification and sends them to the downstream node; Step S5: The sink node receives the data packets sent by the adjacent intermediate node and performs a legality verification on the received data packets, and decodes the data packets that pass the legality verification to obtain a data vector matrix P; where the source node uses the data vector set X p to generate encoded data packets, including: The data vector generated by encoding is as follows: where c i is an encoding coefficient randomly selected from a preset finite field F q ; is a data vector in the data vector set X p ; Set a hop count L for each data vector generated by encoding. The initial value of the hop count L is set to 0 and is attached to the tail of the data vector generated by encoding to form a data packet; where the source node uses the data vector set X q to generate a verification vector including: Using a random vector to fill the data vector set into a set C of m vectors q : Random vector whose elements are randomly obtained from a preset finite field F q and the random vector is linearly independent of the data vector set ; Solve the system of equations by Gaussian elimination Find the matrix composed of linearly independent vectors that satisfy the equation Use the matrix To span the linear space of C q Span the linear space Use the linear equation to obtain the null space Arbitrarily select a basis in the null space Perform a linear combination to generate the verification vector In steps S3 and S5, the legality verification of the received data packets includes: (S31) The node obtains the data packet carrying the hop count information and will create flag z and T receive parameter information is attached to the head of the data vector in the received data packet to obtain the processed data packet; where flag z represents the verification status of the data vector, and set the value of flag z to 0, indicating that it has not been verified yet; T receive represents the current system time received by node v; (S32) Judge the node working status; In response to the parameter T = 0 indicating the working state of the node, it is explained that the node is in a normal working state, and it is judged whether the number of hops L passed by the processed data packet since the last security verification exceeds the preset maximum number of hops L max , in response to L exceeding L max , then wait for the next security verification. If it does not exceed, skip the security verification and wait for encoding and forwarding; In response to T > 0, it indicates that the node is in an abnormal working state. All data packets received by the node in this state need to undergo security verification before they can continue to be transmitted; the initial value of the parameter T is 0; After the node receives the authentication vectors, it only retains a series of the most recently sent authentication vectors, and forms these latest authentication vectors into an authentication vector matrix B v , the intermediate node v will send the random linear combination of the vectors in the authentication vector matrix B v as an authentication vector, and transmits it to the downstream node through the network link; Verify with the verification vector matrix B v to verify those data packets whose reception time is not later than B v transmission time and have not been verified, that is, flag z = 0, T receive ≤ T now -Δ data vectors; Δ is the maximum time difference between the node and the source node, and the network has achieved synchronization; B s is the matrix obtained by deleting the system time parameter from B v ; determine whether the data vector can pass the verification: in response to being established, the data vector passes the verification; otherwise, the data vector cannot pass the verification and is regarded as a contaminated data packet and discarded; The said step S4 includes: (S41) Whenever there is a new verified data vector, the intermediate node v performs a random linear combination of all the verified data vectors to generate a new data packet and sends it to the downstream nodes; assume there are l data vectors The encoding process is as follows: where η i is a random element in the preset finite field F q ; (S42) The new packet hop count L is updated to:

2. The adaptive secure network coding method based on the null space according to claim 1, wherein In step S1, the data vector matrix P to be transmitted is expanded using an identity matrix to obtain an extended data vector matrix X, including: The data vector matrix P consists of m linearly independent n-dimensional data vectors of the same generation, An n×n identity matrix for recording encoding coefficients is added before the data vector matrix P to obtain an extended data vector matrix X; In step S1, the extended data vector matrix X is block-processed to obtain several sets of data vector sets each containing data vectors, including: The chunking rule is: For a preset positive integer, the extended data vector matrix X is divided into several groups of data vector sets, where each group of data vector sets includes data vectors. If the number of the last data vectors is less than they are grouped into one group.

3. The adaptive secure network coding method based on the null space according to claim 1, wherein Step S3 further includes: (S34) Using the verified data vector, set the flag z value to 1, indicating that the security verification has passed, waiting for encoding and forwarding, and set the hop count L in the data packet to 0. At this time, if the state parameter T of this node is > 0, then subtract 1 from the value; if the state parameter T = 0, then keep it unchanged; For the data vector that fails verification, compare the status parameter T of the intermediate node with the preset maximum status parameter T max as follows: When the state parameter T of the intermediate node is less than the preset maximum state parameter T max , increase the value of the state parameter T of the node by L min L is the minimum number of hops in the data packets detected as contaminated during a certain time period, and γ and λ are preset parameters dynamically adjusted according to the needs of network security. The data vectors that do not pass the verification are regarded as contaminated data packets and discarded; When the state parameter T of the intermediate node ≥ T max a reminder will be sent to the upstream node through the security channel pre-arranged in the network system to batch verify the data packets received by the upstream node. If the batch verification fails, the state parameter T of the upstream node will increase and the contaminated data packet will be located through information search technology and the contaminated data packet will be discarded.

4. The zero-space based adaptive secure network coding method according to claim 1, characterized in that The said step S5 includes: (S51) When the data packet reaches the sink node, verify the legality of the data packet; (S52) When the sink node receives m linearly independent data vectors that pass the data packet legality verification, decode the original data vectors according to the inverse matrix of its identity matrix to form a data vector matrix P.

5. An adaptive secure network coding device based on the null space, characterized in that Including a processor and a storage medium; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method according to any one of claims 1 to 4.

6. A storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 4.