Font Size: a A A

Research And Application On SM1 Card Of The Oscca In Distributed Comware Cryptographic Framework

Posted on:2017-04-21Degree:MasterType:Thesis
Country:ChinaCandidate:X Q FengFull Text:PDF
GTID:2308330485985388Subject:Computer Science and Technology
Abstract/Summary:
With the rapid development of commercial banks, the Internet-based applications, which represent commercial banks, are becoming more and more common. The openness and anonymity of the internet as well as highly sensitive of personal financial information, inevitably lead to many security risks. Therefore, the network transmission must ensure data confidentiality, integrity, and reliability identity. This requires the network equipments provide secure and accountable services during the transmission, such as data encryption, digital signatures and e-commerce security certification and so on, so that to prevent the data and resource from being stolen, and the system from being attacked.Compared with the general hardware encryption card, the SMI card of the office of security Commercial Code Administration (OSCCA) in this thesis supports the algorithm of OSCCA. Besides, the algorithm is encapsulated in the chip, thus all operations involved in the data encryption and decryption are completed within the chip, and the outside world cannot access, so as to strengthen the security of network transmission. In order to better promote the SM1 card of OSCCA, this thesis studies the application and implementation of the SM1 card in distributed Comware Cryptographic Framework (CCF).The current SM1 card does not support the distributed device. In order to solve this problem, the thesis firstly introduces the conception of "virtual card". The common line cards in the same network device can use the SM1 algorithm on the SM1 card of OSCCA for data encryption and decryption without supporting the SMI algorithm. In addition, the thesis has implemented a dynamic election among cards of CCF. Current CCF uses a static election among cards. However, the SM1 card of OSCCA has many small cards. In this case, the static election may lead to load unbalance. In order to achieve a better load balance among each card, the thesis presents a dynamic policy to choose a card. According to the key performance indicators of each card (current resident sessions and the session activity), the CCF traverses the statistical information of each small card, calculates the load and switches the sessions among different small cards. Then the thesis uses the Spirent TestCenter creates crypto sessions and matches different IPSec traffic to compare the performance between the static and dynamic choice among cards. The result shows that the performance of dynamic choice among cards is much better than that of static with the increase of sessions and IPSec traffics. In conclusion, the dynamic policy can effectively balance the load in each card.Finally, the thesis validates the basic functions and forwarding performance of the SM1 card of OSCCA, using the TestCenter and related network devices to build the testing environments. The result shows that the SM1 card of OSCCA gets great improvement on forwarding performance.
Keywords/Search Tags:Comware Cryptographic Framework, SM1 card of OSCCA, virtual card, data encryption and decryption, dynamic policy on choosing cards
Related items