论文部分内容阅读
SDH专线是一种目前广泛应用的企业专线,对于重要企业和部门,其安全性至关重要。文中首先简单介绍了SDH及SDH专线的概念,分析了SDH专线的特点和应用方式,然后通过讨论SDH专线的协议分层结构,比较了在不同层次上加密的优缺点,重点是对网络层和物理层加密的比较。接着详细论述了虚容器加密的原理和加密点,给出了点对点和点对多点两种应用方式下的加密方案,论述了虚容器加密在实际应用中的两种实现方式。最后,结合测试结果和理论分析得出结论,相对于IPSec网络层加密,基于虚容器的物理层加密具有线速处理、低时延、低丢包率的特点,是解决SDH专线信息安全的较好方案,尤其适合对服务质量要求较高的实时业务应用。
SDH Line is a currently widely used enterprise leased line, which is crucial to the security of key enterprises and departments. In this paper, the concept of SDH and SDH leased line is briefly introduced. The characteristics and application of SDH leased line are analyzed. Then, by discussing protocol hierarchy of SDH leased line, the advantages and disadvantages of encryption at different levels are compared. The emphasis is on network layer and Physical layer encryption comparison. Then, the principle and encryption point of virtual container encryption are discussed in detail. The encryption schemes under point-to-point and point-to-multipoint applications are given. Two implementations of virtual container encryption in practical applications are discussed. Finally, based on the test results and theoretical analysis, it is concluded that, compared with the IPSec network layer encryption, virtual container-based physical layer encryption is characterized by wire-speed processing, low latency and low packet loss ratio. A good solution, especially for real-time business applications that require high quality of service.