WO2018040605A1 - 数据处理方法、装置及计算机存储介质 - Google Patents

数据处理方法、装置及计算机存储介质 Download PDF

Info

Publication number
WO2018040605A1
WO2018040605A1 PCT/CN2017/082632 CN2017082632W WO2018040605A1 WO 2018040605 A1 WO2018040605 A1 WO 2018040605A1 CN 2017082632 W CN2017082632 W CN 2017082632W WO 2018040605 A1 WO2018040605 A1 WO 2018040605A1
Authority
WO
WIPO (PCT)
Prior art keywords
encryption
mode
decryption
configuration information
current path
Prior art date
Application number
PCT/CN2017/082632
Other languages
English (en)
French (fr)
Inventor
吕华磊
Original Assignee
深圳市中兴微电子技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市中兴微电子技术有限公司 filed Critical 深圳市中兴微电子技术有限公司
Publication of WO2018040605A1 publication Critical patent/WO2018040605A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04JMULTIPLEX COMMUNICATION
    • H04J3/00Time-division multiplex systems
    • H04J3/16Time-division multiplex systems in which the time allocation to individual channels within a transmission cycle is variable, e.g. to accommodate varying complexity of signals, to vary number of channels transmitted
    • H04J3/1605Fixed allocated frame structures
    • H04J3/1652Optical Transport Network [OTN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • H04L9/16Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords

Definitions

  • the present invention relates to the field of encryption and decryption technology of an optical transport network, and in particular, to a data processing method, apparatus, and computer storage medium.
  • OTN is a transmission network based on wavelength division multiplexing technology for organizing networks in the optical layer.
  • the transmitted data needs to be encrypted, and then the ciphertext is decrypted after passing through the OTN network, thereby obtaining plaintext.
  • the data transmission process of the OTN network usually uses a single mode to encrypt and decrypt data, so that the encrypted data is easily cracked, and the security of data transmission is low.
  • the embodiments of the present invention are intended to provide a data processing method, apparatus, and computer storage medium, which can ensure the accuracy of OTN data on the basis of effectively improving the security of OTN data transmission.
  • the invention provides a data processing method, the method comprising:
  • the first mode configuration information includes: an encryption and decryption mode, an error check and an error (ECC) check Value, reserved overhead location;
  • ECC error check
  • the confirming that the current path preparation is completed with the encryption end includes:
  • the first current path preparation completion message includes a first path ECC check value
  • the second current path preparation completion message includes a second path ECC check value.
  • the acquiring, by the encryption end, the first current path preparation completion message sent by using the overhead bus includes:
  • the monitoring of the cryptographic characters inserted in the reserved overhead position of the current OTN frame and the preset condition include:
  • the method further includes:
  • the preset condition is The encryption side sends a message to cancel the insertion plus password word.
  • the encryption and decryption mode is any one of an Electronic Codebook Book (ECB) mode, a Counter (CTR) mode, and a pass-through mode.
  • EBC Electronic Codebook Book
  • CTR Counter
  • pass-through mode any one of an Electronic Codebook Book (ECB) mode, a Counter (CTR) mode, and a pass-through mode.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the data processing method according to the embodiment of the invention.
  • the invention provides a data processing method, the method comprising:
  • the acquiring, by the decryption end, the first mode configuration information includes:
  • the confirming that the current path preparation is completed with the decryption end comprises:
  • the acquiring, by the decryption end, the second current path preparation completion message sent by using the overhead bus includes:
  • the inserting a password in the reserved overhead position of the current OTN frame according to the first mode configuration information includes:
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the data processing method according to the embodiment of the invention.
  • the present invention provides a data processing apparatus, the apparatus comprising:
  • the transceiver module is configured to send the first mode configuration information to the encryption end;
  • a processing module configured to: after confirming that the current path preparation is completed with the encryption end, configuring an encryption and decryption mode according to the first mode configuration information;
  • the updating module is configured to update the first mode configuration information to the second mode configuration information when the cryptographic characters inserted in the reserved overhead position of the current OTN frame are combined with the preset condition;
  • the transceiver module is further configured to send the second mode configuration information to the encryption end.
  • the transceiver module is further configured to acquire a first current path preparation completion message sent by the encryption terminal through the overhead bus, and send, by using the overhead bus, the second current path ready to be completed to the decryption end. Message.
  • the transceiver module is further configured to acquire a first current path preparation completion message sent by the encryption terminal through the overhead bus in a first time period and conforming to a first path ECC check rule.
  • the data processing apparatus further includes: a determining module configured to monitor, in the second time period, the insertion of the frame header multiframe number position of the current OTN frame into the reserved overhead position Whether the valid character of the password word is greater than or equal to a preset threshold, and if the valid character of the encryption code is greater than or equal to the preset threshold, determining that the frame header multiframe number position of the current OTN frame starts to the reserved overhead position The added password character is inserted in the preset condition.
  • a determining module configured to monitor, in the second time period, the insertion of the frame header multiframe number position of the current OTN frame into the reserved overhead position Whether the valid character of the password word is greater than or equal to a preset threshold, and if the valid character of the encryption code is greater than or equal to the preset threshold, determining that the frame header multiframe number position of the current OTN frame starts to the reserved overhead position The added password character is inserted in the preset condition.
  • the transceiver module is further configured to receive the location within the second time period.
  • the encryption code sent by the encryption end inserts the success message, and the cryptographic character inserted in the reserved overhead position of the current OTN frame is detected, the cancel insertion and encryption code message is sent to the encryption end.
  • the invention further provides a data processing device, the device comprising:
  • transceiver module configured to acquire first mode configuration information sent by the decryption end
  • a processing module configured to configure an encryption and decryption mode according to the first mode configuration information after confirming that the current path preparation is completed with the decryption end;
  • the processing module is further configured to insert a cryptographic word in the reserved overhead position of the current OTN frame according to the first mode configuration information, and generate a cryptographic word insertion success message;
  • the transceiver module is further configured to send the encryption password insertion success message to the decryption end until receiving the cancel insertion encryption password message sent by the decryption terminal.
  • the transceiver module is further configured to acquire first mode configuration information that is sent by the decryption terminal through the overhead bus in a third time period and conforms to a mode ECC check rule.
  • the transceiver module is further configured to send a first current path preparation completion message to the decryption end by using an overhead bus, and acquire a second current path prepared by the decryption end by using the overhead bus. Message.
  • the transceiver module is further configured to acquire a second current path preparation completion message sent by the decryption end through the overhead bus in a fourth time period and conform to a second ECC check rule.
  • the processing module is further configured to start inserting a ciphering word into the reserved overhead position at a frame header multiplex frame number position of the current OTN frame according to the first mode configuration information.
  • the data processing method and device and the computer storage medium provided by the embodiment of the present invention send the first mode configuration information to the encryption end through the decryption end, and confirm the current channel standard with the encryption end.
  • the encryption and decryption mode is configured according to the first mode configuration information; and the first mode configuration information is updated when the cryptographic characters inserted in the reserved overhead position of the current OTN frame are combined with the preset condition.
  • Configuring information for the second mode transmitting the second mode configuration information to the encrypted end.
  • the embodiment of the present invention can implement non-stop switching between multiple encryption and decryption modes in the data transmission process of the OTN network, so as to ensure the accuracy of the OTN data transmission, the accuracy of the OTN data can be ensured. Enhance the transmission performance of OTN systems.
  • Embodiment 1 is a flowchart of Embodiment 1 of a data processing method according to the present invention
  • Embodiment 2 is a flowchart of Embodiment 2 of a data processing method according to the present invention
  • Embodiment 3 is a flowchart of Embodiment 3 of a data processing method according to the present invention.
  • FIG. 4 is a schematic structural diagram of an OTN frame according to an embodiment of a data processing method according to the present invention.
  • FIG. 5 is a detailed mode switching flowchart of an embodiment of a data processing method according to the present invention.
  • FIG. 6 is a schematic structural diagram 1 of an embodiment of a data processing apparatus for switching between encryption and decryption modes according to the present invention
  • FIG. 7 is a second schematic structural diagram of an embodiment of a data processing apparatus for switching between encryption and decryption modes according to the present invention.
  • FIG. 1 is a flowchart of a first embodiment of a data processing method according to the present invention. As shown in FIG. 1 , a data processing method provided by an embodiment of the present invention may include the following steps:
  • Step 101 Send the first mode configuration information to the encryption end.
  • the decryption end inserts the first mode configuration information into the overhead of the OTN data by using the overhead bus, and sends the first mode configuration information to the encryption end; wherein the first mode configuration information includes an encryption and decryption mode, a mode ECC check Value, reserved cost location.
  • Step 102 After confirming that the current path preparation is completed with the encryption end, configure an encryption and decryption mode according to the first mode configuration information.
  • the first current path preparation completion message sent by the terminal through the overhead bus returns to step 101; if the decryption end acquires the first current path preparation completion message sent by the encryption end through the overhead bus, the overhead of the decryption end to the OTN data Inserting a second current path preparation completion message, and transmitting, by the overhead bus, a second current path preparation completion message to the encryption end.
  • the first current path preparation completion message includes a first path ECC check value
  • the second current path preparation completion message includes a second path ECC check value
  • Step 103 Update the first mode configuration information to the second mode configuration information when the cryptographic characters inserted in the reserved overhead position of the current OTN frame are combined with the preset condition.
  • the decryption end determines whether the valid character of the encryption code is greater than or equal to a preset threshold; if the valid character of the encryption code is greater than or equal to the preset threshold, for example, 5 or more are detected within 8 frames, Determining, in the frame header multiframe number position of the current OTN frame, the cryptographic character inserted into the reserved overhead position and a preset condition, wherein the decryption end is at the frame header multiframe number position of the next round of the OTN frame.
  • the first mode configuration information is updated to the second
  • the encryption code can be set to 0x11 in the ECB mode, 0x22 in the CTR mode, and 0x33 in the through mode. This is only an example, and the application can be set according to actual needs.
  • Step 104 Send the second mode configuration information to the encryption end.
  • the decryption terminal After updating the first mode configuration information to the second mode configuration information, the decryption terminal inserts the second mode configuration information into the overhead of the OTN data through the overhead bus, and sends the information to the encryption terminal.
  • the data processing method provided by the first embodiment of the present invention sends the first mode configuration information to the encryption end through the decryption end;
  • the first mode configuration information includes: an encryption and decryption mode, a mode ECC check value, and a reserved overhead position;
  • the encryption and decryption mode is configured according to the first mode configuration information;
  • the preset password is inserted in the reserved overhead position of the current OTN frame, the preset condition is
  • the first mode configuration information is updated to the second mode configuration information; and the second mode configuration information is sent to the encrypted end.
  • the non-stop switching between multiple encryption and decryption modes in the data transmission process of the OTN network can be realized, and the accuracy of the OTN data can be ensured on the basis of effectively improving the security of the OTN data transmission, thereby enhancing the transmission of the OTN system. performance.
  • the embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the data processing method according to the first embodiment of the present invention.
  • FIG. 2 is a flowchart of a second embodiment of a data processing method according to the present invention. As shown in FIG. 2, the data processing method provided by the embodiment of the present invention may include the following steps:
  • Step 201 Acquire first mode configuration information sent by the decryption end.
  • the encryption terminal obtains the first mode configuration information sent by the decryption terminal from the overhead of the OTN data by using the overhead bus.
  • the first mode configuration information includes: an encryption and decryption mode, a mode ECC check value, and a reserved overhead location.
  • the encryption end determines whether the first mode configuration information sent by the decryption end through the overhead bus is obtained in the third time period, and if the first mode configuration information is obtained, Step 202 is performed; otherwise, the determination is made again.
  • Step 202 After confirming that the current path preparation is completed with the decryption end, configuring an encryption and decryption mode according to the first mode configuration information.
  • the encryption end inserts a first current path preparation completion message into the overhead of the OTN data through the overhead bus, and sends the message to the decryption end; the encryption end determines whether the decryption end meets the second ECC check rule in the fourth time period.
  • the second current path preparation completion message sent by the overhead bus if the encryption end acquires the second current path preparation completion message in the fourth time period, step 203 is performed; otherwise, the process returns to step 201.
  • the first current path preparation completion message includes a first path ECC check value
  • the second current path preparation completion message includes a second path ECC check value
  • Step 203 Insert a password encryption word in the reserved overhead position of the current OTN frame according to the first mode configuration information, and generate a password insertion success message, and send the encryption password insertion success message to the decryption end. Until the cancel insertion plus password message sent by the decryption terminal is received.
  • the encryption end inserts a ciphering word into the reserved overhead position at the frame header multiframe number position of the current OTN frame according to the first mode configuration information, and continuously inserts 8 cipher words; after the cryptographic word insertion is completed, the cipher is generated.
  • the word insertion success message is sent to the decryption end until the decryption end is received.
  • the canceled insertion plus password word message is sent to stop the insertion of the password word.
  • the encryption code can be set to 0x11 in the ECB mode, 0x22 in the CTR mode, and 0x33 in the through mode. This is only an example, and the application can be set according to actual needs.
  • the data processing method provided by the second embodiment of the present invention acquires the first mode configuration information sent by the decryption end by using the encryption end;
  • the first mode configuration information includes: an encryption and decryption mode, a mode ECC check value, and a reserved overhead location; After confirming that the current path preparation is completed with the decryption end, configuring an encryption and decryption mode according to the first mode configuration information; inserting a encryption code into the reserved overhead position of the current OTN frame according to the first mode configuration information, and And generating a cipher insertion success message, and sending the cipher insertion success message to the decryption end until receiving the cancel insertion cipher message sent by the decryption end.
  • the non-stop switching between multiple encryption and decryption modes in the data transmission process of the OTN network can be realized, and the accuracy of the OTN data can be ensured on the basis of effectively improving the security of the OTN data transmission, thereby enhancing the transmission of the OTN system. performance.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the data processing method according to the second embodiment of the invention.
  • FIG. 3 is a flowchart of a third embodiment of the data processing method of the present invention. As shown in FIG. 3, the data processing method provided by the embodiment of the present invention may include the following steps:
  • Step 301 The decryption end sends the first mode configuration information to the encryption end.
  • the decryption end controller inserts the first mode configuration information into the OTN data overhead through the overhead bus, and sends the first mode configuration information to the encryption terminal.
  • the first mode configuration information includes: an encryption and decryption mode, a mode ECC check value, and a reserved overhead location.
  • the encryption and decryption mode is any one of a phonebook ECB mode, a counter CTR mode, and a through mode;
  • the mode ECC check value is implemented by adding a check bit to the data to be verified; wherein the added bit data is 1 or 0.
  • Step 302 The encryption end determines whether the first mode configuration information is obtained in the third time period.
  • the encryption terminal starts the timer 3, sets the timer time of the timer 3 to the third time, for example, is set to 3s, and the encryption end controller determines whether the OTN overhead is obtained by the decryption terminal through the overhead bus within 3s.
  • the first mode configuration information if the encryption end controller does not obtain the first mode configuration information within 3s, executing step 303; if the encryption end controller acquires the first mode within 3s For configuration information, go to step 304.
  • Step 303 The encryption end waits to enter the next judgment period.
  • the encryption end controller When the encryption end controller does not acquire the first mode configuration information within 3 seconds, it waits for the next cycle to re-determine.
  • Step 304 The encryption end determines whether the mode ECC check value in the first mode configuration information conforms to a mode ECC check rule.
  • step 305 if the mode ECC check value in the configuration information does not comply with the mode ECC check rule, step 306 is performed;
  • the mode ECC check rule is determined according to the set ECC check value and the read ECC code.
  • Step 305 The encryption end does not send the first current path preparation completion message to the decryption end.
  • the encryption end controller does not acquire the first mode configuration information or the mode ECC check value in the acquired first mode configuration information does not conform to the mode ECC check rule within 3 seconds,
  • the first current path preparation completion message is not sent to the decryption end, and the task is ended to enter the next update cycle.
  • Step 306 The encryption end sends a first current path preparation completion message to the decryption end.
  • the encryption end controller inserts the first mode configuration information in the third time period and the mode ECC check value in the first mode configuration information conforms to the mode ECC check rule, and inserts into the overhead of the OTN data through the overhead bus.
  • the first current path preparation completion message is sent to the decryption end; wherein the first current path preparation completion message includes a first path ECC check value;
  • the first current path preparation completion message may be 0x31, 0x37, etc., wherein the first path ECC check value occupies 4 bits.
  • Step 307 The decryption end determines whether the first current path preparation completion message is acquired within the first time period.
  • the decryption end controller starts the timer 1, sets the time of the timer 1 to the first time, for example, is set to 1 s, and the decryption end controller determines whether the encryption in the OTN overhead is acquired through the overhead bus within 1 s time.
  • a first current path preparation completion message sent by the terminal wherein the first current path preparation completion message includes a first path ECC check value; if the decryption end controller does not acquire the first time within 1 s If the current path preparation completion message is executed, step 308 is performed; if the decryption end controller acquires the first current path preparation completion message within 1 s, step 309 is performed.
  • Step 308 The decryption end waits for the next judgment period.
  • the decryption end controller When the decryption end controller does not acquire the first current path preparation completion message within 1 s, it waits for the next cycle to re-determine.
  • Step 309 The decryption end determines whether the first path ECC check value in the first current path preparation completion message complies with the first path ECC check rule.
  • step 310 When the decryption end controller acquires the first current path preparation completion message within 1 s, determining whether the first path ECC check value in the first current path preparation completion message is Compliance with the first path ECC check rule; if the first path ECC check value does not meet the first path ECC check rule, step 310 is performed; if the first path ECC check value conforms to the first path For the ECC check rule, go to step 311.
  • the first path ECC check rule is determined according to the set ECC check value and the read ECC code.
  • Step 310 The decryption end does not send a second current path preparation completion message to the encryption end.
  • the first path ECC check value in the first current path preparation completion message that is not obtained by the decryption end controller in the first current path preparation completion message or the acquired first current path preparation completion message does not comply with the first path ECC check rule.
  • the second current path preparation completion message is not sent to the encryption end, and the task is terminated to enter the next update period.
  • Step 311 The decryption end sends a second current path preparation completion message to the encryption end.
  • the decryption end controller inserts a second current path preparation completion message into the OTN data overhead by using the overhead bus; the second current path preparation completion message includes a second path ECC check value;
  • the second current path preparation completion message may be 0x41, 0x47, etc., wherein the first path ECC check value occupies 4 bits.
  • Step 312 The encryption end determines whether the second current path preparation completion message is acquired in the fourth time period.
  • the encryption end controller starts the timer 4, sets the timer time of the timer 4 to the fourth time, for example, is set to 4s, and the encryption end controller determines whether the decryption in the OTN overhead is acquired through the overhead bus within 4s.
  • a second current path preparation completion message sent by the terminal wherein the second current path preparation completion message includes a second path ECC check value;
  • step 313 If the encryption end controller does not obtain the second current path preparation completion message within 4s, step 313 is performed; if the encryption end controller acquires the second current path preparation completion message within 4s, Then perform step 314;
  • Step 313 The encryption end waits for the next update cycle.
  • the encryption end controller does not acquire the second current path preparation completion message within 4 seconds, the end of the current task waits for the next update cycle to restart the task.
  • Step 314 The encryption end determines whether the second path ECC check value in the second current path preparation completion message complies with the second path ECC check rule.
  • step 315 determining, by the encryption end controller, whether the second path ECC check value in the second current path preparation completion message meets the second path ECC check rule when the second current path preparation completion message is acquired within a time of 4s If the second path ECC check value does not meet the second path ECC check rule, step 315 is performed; if the second path ECC check value meets the second path ECC check rule, step is performed 316.
  • the second path ECC check rule is determined according to the set second path ECC check value and the read ECC code.
  • Step 315 The encryption and decryption mode is not configured to the encryption end.
  • the encryption terminal configures the encryption and decryption mode, and ends the current task and waits for the next update cycle to restart the task.
  • Step 316 The encryption end configures the encryption and decryption mode according to the first mode configuration information.
  • the encryption end controller acquires the second current path preparation completion message in a time of 4s and the second path ECC check value in the second current path preparation completion message conforms to the second path ECC check rule, according to
  • the acquired first mode configuration information is configured with an encryption and decryption mode to the encryption end, and the mode confirmation is completed;
  • the encryption/decryption mode is any one of a phonebook ECB mode, a counter CTR mode, and a through mode.
  • Step 317 The encryption end sends a release overhead bus notification to the decryption end.
  • the encryption end controller acquires the second current path preparation completion message within 4s And when the second path ECC check value in the second current path preparation completion message conforms to the second path ECC check rule, the encryption end releases the overhead bus, and sends a release overhead bus notification to the decryption end.
  • Step 318 The decryption end determines whether a release overhead bus notification is received.
  • step 320 After the decryption end sends the second current path preparation completion message to the encryption end, it determines whether the release overhead bus notification is received; if the decryption end does not receive the release overhead bus notification, step 319 is performed; if the decryption end receives the release overhead bus notification Then, step 320 is performed.
  • Step 319 The decryption end continues to determine whether a release overhead bus notification is received.
  • the decryption end When the decryption end does not receive the release overhead bus notification, it continues to determine whether to receive the release overhead bus notification until the release overhead bus notification is received.
  • Step 320 The decryption end configures an encryption and decryption mode according to the first mode configuration information.
  • the decryption end After receiving the release overhead bus notification sent by the encryption end, the decryption end confirms that the current path preparation is completed with the encryption end. At this time, the decryption end controller configures the encryption and decryption mode to the decryption end according to the first mode configuration information, and completes the mode confirmation.
  • the encryption/decryption mode is any one of a phonebook ECB mode, a counter CTR mode, and a through mode.
  • Step 321 The encryption end inserts a password added word in the reserved overhead position of the current OTN frame, and generates a password insertion success message.
  • the encryption code can be set to 0x11 in the ECB mode, 0x22 in the CTR mode, and 0x33 in the through mode. This is only an example, and the application can be set according to actual needs.
  • Step 322 The encryption end sends a password insertion success message to the decryption end.
  • the encryption terminal After the encryption terminal inserts the encryption code in the reserved overhead position of the current OTN frame and generates a password insertion success message, the encryption password insertion success message is sent to the decryption end.
  • Step 323 The decryption end determines whether the cryptographic word insertion success message sent by the encryption terminal is received in the second time period and the cryptographic character is combined with the preset condition.
  • the timer 2 is started, and the timer time of the timer 2 is set to the second time, for example, set to 2s; the decryption terminal determines whether the encrypted terminal is received within the time period of 2s.
  • the decryption end performs step 329 to step 331 while performing step 323.
  • Step 324 The decryption end does not send a cancel insertion plus password message to the encryption end.
  • the decryption end does not receive the encryption code insertion success message sent by the encryption terminal within the time period of 2s, or the decryption end does not detect the encryption code word or the detected encryption code word valid character is less than the preset threshold value, the decryption end
  • the cancel insertion plus password word message is not sent to the encryption end, and waits for the next update period to re-determine.
  • Step 325 The decryption end sends a cancel insertion plus password message to the encryption end.
  • the decryption end receives the encryption code insertion success message sent by the encryption terminal in the second time period, that is, the time period of 2s, and monitors the frame header multiframe number MFAS[2:0 in the current OTN frame.
  • the message of canceling the insertion of the encryption code is sent to the encryption end.
  • Step 326 The encryption end determines whether a message to cancel the insertion of the encryption code is received.
  • the encryption end determines whether the cancel insertion plus password word message sent by the decryption end is received. If the encryption end does not receive the cancel insertion plus password word message sent by the decryption end, step 327 is performed; if the encryption end receives the transmission by the decryption end To cancel the insert plus password word message, go to step 328.
  • Step 327 The encryption terminal continues to insert the encryption code.
  • the encryption terminal After the encryption terminal inserts the encryption code in the reserved overhead position of the current OTN frame, if the cancel insertion encryption password message is not received, the encryption password is continuously inserted.
  • Step 328 The encryption end cancels the insertion of the encryption code.
  • the encryption terminal After the encryption terminal inserts the encryption code in the reserved overhead position of the current OTN frame, if the cancel insertion encryption code message sent by the decryption terminal is received, the insertion of the encryption code word is cancelled, and the code word of the next update period is waited for. insert.
  • Step 329 The decryption end determines whether the encryption code is detected in the second time period and whether the monitored encryption code meets the preset condition.
  • the encryption code can be set to 0x11 in the ECB mode, 0x22 in the CTR mode, and 0x33 in the through mode. This is only an example, and can be set according to actual needs in the application.
  • Step 330 The decryption end does not update the first mode configuration information to the second mode configuration information.
  • the preset threshold is less than the preset condition, the decryption end does not update the first mode configuration information to the second mode configuration information, but the frame header of the next round of the OTN frame is multiframed.
  • Step 331 The decryption end updates the first mode configuration information to the second mode configuration information.
  • the first mode configuration information is updated to the second mode configuration information, that is, the mode switching is completed; wherein the second mode configuration information includes: an encryption and decryption mode, a mode ECC check value, reserved overhead location.
  • the decryption end will use the first mode.
  • the configuration information is updated to the second mode configuration information, and the mode is switched.
  • FIG. 4 is a schematic structural diagram of an OTN frame according to an embodiment of a data processing method according to the present invention; as shown in FIG. 4, an OTN frame is mainly composed of a reserved overhead portion and an Optical Channel Payload Unit-k (OPUk) portion. ;
  • OPUk Optical Channel Payload Unit-k
  • the reserved cost of the OTN is a field that provides the user with some specific requirements, such as a field for monitoring the message; includes an Optical Transform Unit (OTU) overhead, an Optical Channel Data Unit (ODU) overhead, and a light.
  • OTU Optical Transform Unit
  • ODU Optical Channel Data Unit
  • RES future international standardization
  • Each reservation overhead of the OTN frame occupies one byte.
  • the mode acknowledgment uses a reserved overhead location OTU overhead to complete the mode acknowledgment; the insertion of the cryptographic word and the monitoring of the cryptographic word use the RES overhead location.
  • the pass-and-add password word is used; the mode switch uses the mode and the mode to confirm the same overhead position to pass the codeword insertion success information, the codeword monitoring success information, and the uninsertion codeword information, that is, the OTU overhead.
  • the present invention encrypts only the optical path payload unit k portion of the OTN frame, and does not encrypt the overhead portion.
  • FIG. 5 is a detailed mode switching flowchart of the data processing method according to the present invention. As shown in FIG. 5, after the encryption end and the decryption end complete the mode confirmation, the encryption and decryption operations are started.
  • each codeword occupies 1 byte, and specifies that the encryption code in ECB mode is 0x11, the password word in CTR mode is 0x22, and the password in passthrough mode is 0x33.
  • the present invention uses this overhead to determine the encrypted frame number and the start of using the new encryption and decryption mode. Decrypting the frame number ensures that the location of encryption and decryption is the same, thus achieving the effect of lossless switching and ensuring the accuracy of the data.
  • the data processing method provided by the third embodiment of the present invention sends the first mode configuration information to the encryption end through the decryption end; the encryption end determines whether the first mode configuration information is obtained in the third time period; the encryption end acquires the first mode. Determining, by the configuration information, whether the mode ECC check value in the first mode configuration information conforms to a mode ECC check rule; the encrypting end sends the mode to the decryption end when the mode ECC check value conforms to the mode ECC check rule a current path ready to complete message; Determining whether the first current path preparation completion message is obtained in the first time period; the decryption end determining the first path ECC in the first current path preparation completion message after acquiring the first current path preparation completion message Whether the verification value meets the first path ECC check rule; the decryption end sends a second current path preparation completion message to the encryption end when the first path ECC check value conforms to the first path ECC check rule; the encryption end determines whether it is in the fourth Obtaining a
  • the password word is inserted into the success message and the password-added character is combined with the preset condition; when the decryption terminal receives the encryption code insertion success message within the second time period and the password-added character is combined with the preset condition, Sending a message to cancel the insertion and adding a password word to the encryption end; the encryption end determines whether the message of canceling the insertion of the encryption code is received; after receiving the message of canceling the insertion of the encryption word, the encryption end cancels the insertion of the encryption word; meanwhile, the decryption end judges that Whether the encryption code is detected in the second time period and the monitored encryption code meets the preset condition; when the decryption terminal detects the encryption code in the second time period and the monitored encryption character is combined with the preset condition, Updating the first mode configuration information to the second mode configuration information.
  • the embodiment of the present invention can implement non-stop switching between multiple encryption and decryption modes in the data transmission process of the OTN network, and can ensure the accuracy of the OTN data and enhance the accuracy of the OTN data transmission. Transmission performance of the OTN system.
  • An embodiment of the present invention further provides a computer storage medium, where the computer storage medium is stored Computer executable instructions are stored for performing the data processing method of the embodiments of the present invention.
  • FIG. 6 is a schematic structural diagram of an embodiment of a data processing apparatus for switching between encryption and decryption modes according to the present invention
  • the data processing apparatus 06 for switching between encryption and decryption modes according to an embodiment of the present invention includes: a transceiver module 61 and a processing module. 62, an update module 63; wherein
  • the transceiver module 61 is configured to send first mode configuration information to the encryption end;
  • the first mode configuration information includes: an encryption and decryption mode, a mode ECC check value, and a reserved overhead location;
  • the encryption and decryption mode is any one of a phonebook ECB mode, a counter CTR mode, and a through mode;
  • the processing module 62 is configured to: after confirming that the current path preparation is completed with the encryption end, configuring an encryption and decryption mode according to the first mode configuration information;
  • the updating module 63 is configured to update the first mode configuration information to the second mode configuration information when the cryptographic characters inserted in the reserved overhead position of the current OTN frame are combined with the preset condition;
  • the transceiver module 61 is further configured to send the second mode configuration information to the encryption end.
  • the transceiver module 61 is further configured to acquire a first current path preparation completion message sent by the encryption terminal through the overhead bus; the first current path preparation completion message includes a first path ECC. a check value; sending, by the overhead bus, a second current path preparation completion message to the decryption end; the second current path preparation completion message includes a second path ECC check value.
  • the transceiver module 61 is further configured to acquire the first current path prepared by the encryption terminal by using the overhead bus in the first time period and conforming to the first path ECC check rule. Message.
  • the data processing device 06 further includes: a determining module 64;
  • the determining module 64 is configured to monitor the frame header multiframe in the current OTN frame in the second time period Whether the valid character of the ciphering word inserted into the reserved cost position is greater than or equal to a preset threshold, and if the valid character of the ciphering word is greater than or equal to the preset threshold, determining the current OTN frame
  • the frame header multiframe number position starts to add a ciphering character to the reserved overhead position and a preset condition
  • the encryption code may be 0x11 in the ECB mode, 0x22 in the CTR mode, or 0x33 in the through mode, or may be set to other codes, which is not limited herein.
  • the transceiver module 61 is further configured to receive the cryptographic word insertion success message sent by the encryption terminal during the second time period, and monitor the reserved overhead position in the current OTN frame. When the cryptographic character inserted in the preset condition is combined, the cancel insertion plus password message is sent to the encrypted end.
  • the device in this embodiment may be used to implement the technical solution of the foregoing method embodiment, and the implementation principle and the technical effect are similar, and details are not described herein again.
  • the transceiver module 61, the processing module 62, the update module 63, and the determination module 64 may each be a central processing unit (CPU) in the data processing device 06 that is switched between the encryption and decryption modes.
  • Realizer Micro Processor Unit, MPU
  • DSP Digital Signal Processor
  • FPGA Field Programmable Gate Array
  • FIG. 7 is a schematic structural diagram of an embodiment of a data processing apparatus for switching between encryption and decryption modes according to the present invention.
  • the data processing apparatus 07 for switching between encryption and decryption modes according to an embodiment of the present invention includes: a transceiver module 71 and a processing module. 72; among them,
  • the transceiver module 71 is configured to acquire first mode configuration information sent by the decryption end; the first mode configuration information includes: an encryption and decryption mode, a mode ECC check value, and a reserved overhead location;
  • the encryption/decryption mode is any one of a phonebook ECB mode, a counter CTR mode, and a through mode.
  • the processing module 72 is configured to configure an encryption and decryption mode according to the first mode configuration information after confirming that the current path preparation is completed with the decryption end;
  • the processing module 72 is further configured to insert a cryptographic word in the reserved overhead position of the current OTN frame according to the first mode configuration information, and generate a cryptographic word insertion success message;
  • the transceiver module 71 is further configured to send the encryption code insertion success message to the decryption end until receiving the cancel insertion encryption code message sent by the decryption end.
  • the transceiver module 71 is further configured to acquire first mode configuration information that is sent by the decryption end through the overhead bus in a third time period and conforms to a mode ECC check rule.
  • the transceiver module 71 is configured to send a first current path preparation completion message to the decryption end by using an overhead bus; the first current path preparation completion message includes a first path ECC check value. Obtaining a second current path preparation completion message sent by the decryption end through the overhead bus; the second current path preparation completion message includes a second path ECC check value.
  • the transceiver module 71 is further configured to acquire a second current path preparation completion message sent by the decryption end through the overhead bus in a fourth time period and conform to a second ECC check rule. .
  • the processing module 72 is further configured to start inserting a ciphering word into the reserved overhead position at a frame header multiplex frame number position of the current OTN frame according to the first mode configuration information.
  • the encryption code may be 0x11 in the ECB mode, 0x22 in the CTR mode, or 0x33 in the through mode, or may be set to other codes, which is not limited herein.
  • the device in this embodiment may be used to implement the technical solution of the foregoing method embodiment, and the implementation principle and the technical effect are similar, and details are not described herein again.
  • the transceiver module 71 and the processing module 72 can be located in the encryption and decryption mode.
  • the CPU, MPU, DSP, FPGA, etc. in the data processing device 07 that is switched between are implemented.
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention can take the form of a hardware embodiment, a software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
  • the data processing method of the embodiment of the present invention sends the first mode configuration information to the encryption end through the decryption end; after confirming that the current path preparation is completed with the encryption end, configuring the encryption and decryption mode according to the first mode configuration information; And detecting, when the preset password is inserted in the reserved overhead position of the current OTN frame, the first mode configuration information is updated to the second mode configuration information; and sending the second mode to the encryption terminal Configuration information.
  • the non-stop switching between multiple encryption and decryption modes can be realized in the data transmission process of the OTN network, and the accuracy of the OTN data can be ensured on the basis of effectively improving the security of the OTN data transmission, thereby enhancing the transmission of the OTN system. performance.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Small-Scale Networks (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer And Data Communications (AREA)
  • Storage Device Security (AREA)

Abstract

本发明实施例公开一种数据处理方法、装置及计算机存储介质,包括:向加密端发送第一模式配置信息;所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置;在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;向所述加密端发送所述第二模式配置信息。

Description

数据处理方法、装置及计算机存储介质 技术领域
本发明涉及光传送网的加解密技术领域,尤其涉及一种数据处理方法、装置及计算机存储介质。
背景技术
随着通信业的发展以及全业务运营时代的到来,电信运营商将转型成为集电信服务、信息技术服务等为一体的综合服务提供商。业务的丰富性带来对带宽的更高需求,直接反映为对传送网能力和性能的要求。由于光传送网(Optical Transport Network,OTN)技术能够满足各种新型业务的需求,故从幕后渐渐走到台前,得以成为传送网发展的主要方向。
OTN是以波分复用技术为基础,用于在光层组织网络的传送网。在OTN网络的数据传输过程中,为了保证网络数据的安全性,需要对传输的数据进行加密,然后经过OTN网络后对密文进行解密,从而得到明文。现有技术在OTN网络的数据传输过程中通常使用单一模式对数据进行加解密,这样加密后的数据很容易遭到破解,数据传输的安全性较低。
发明内容
本发明实施例期望提供一种数据处理方法、装置及计算机存储介质,能够在有效提高OTN数据传输的安全性的基础上,得以保证OTN数据的准确性。
本发明提供一种数据处理方法,所述方法包括:
向加密端发送第一模式配置信息;所述第一模式配置信息包括:加解密模式、模式错误检查和纠正(Error Checking and Correcting,ECC)校验 值、预留开销位置;
在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;
向所述加密端发送所述第二模式配置信息。
在一实施例中,所述在与所述加密端确认当前通路准备完成,包括:
获取由所述加密端通过开销总线发送的第一当前通路准备完成消息;所述第一当前通路准备完成消息中包含有第一通路ECC校验值;
通过所述开销总线向所述加密端发送第二当前通路准备完成消息;所述第二当前通路准备完成消息中包含有第二通路ECC校验值。
在一实施例中,所述获取由所述加密端通过所述开销总线发送的第一当前通路准备完成消息,包括:
获取在第一时间段内且符合第一通路ECC校验规则的由所述加密端通过所述开销总线发送的第一当前通路准备完成消息。
在一实施例中,所述监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件,包括:
在第二时间段内监测到在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字的有效字符是否大于等于预设阈值,若所述加密码字的有效字符大于等于所述预设阈值,则确定在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字符合预设条件。
在一实施例中,所述方法还包括:
在第二时间段内接收到由所述加密端发送的加密码字插入成功消息、且在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,向所述加密端发送取消插入加密码字消息。
在一实施例中,所述加解密模式为电话本(Electronic Codebook Book,ECB)模式、计数器(Counter,CTR)模式、直通模式中的任意一种。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行本发明实施例所述的数据处理方法。
本发明提供一种数据处理方法,所述方法包括:
获取由解密端发送的第一模式配置信息;
在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
根据所述第一模式配置信息在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息,向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。
在一实施例中,所述获取由解密端发送的第一模式配置信息,包括:
获取在第三时间段内且符合模式ECC校验规则的由所述解密端通过开销总线发送的第一模式配置信息。
在一实施例中,所述在与所述解密端确认当前通路准备完成,包括:
通过开销总线向所述解密端发送第一当前通路准备完成消息;
获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
在一实施例中,所述获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息,包括:
获取在第四时间段内且符合第二ECC校验规则的由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
在一实施例中,所述根据所述第一模式配置信息在当前OTN帧的预留开销位置中插入加密码字,包括:
根据所述第一模式配置信息在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入加密码字。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行本发明实施例所述的数据处理方法。
本发明提供一种数据处理装置,所述装置包括:
收发模块,配置为向加密端发送第一模式配置信息;
处理模块,配置为在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
更新模块,配置为在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;
所述收发模块,还配置为向所述加密端发送所述第二模式配置信息。
在一实施例中,所述收发模块,还配置为获取由所述加密端通过开销总线发送的第一当前通路准备完成消息;通过所述开销总线向所述解密端发送第二当前通路准备完成消息。
在一实施例中,所述收发模块,还配置为获取在第一时间段内且符合第一通路ECC校验规则的由所述加密端通过所述开销总线发送的第一当前通路准备完成消息。
在一实施例中,所述数据处理装置还包括:判断模块,配置为在第二时间段内监测到在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字的有效字符是否大于等于预设阈值,若所述加密码字的有效字符大于等于所述预设阈值,则确定在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字符合预设条件。
在一实施例中,所述收发模块,还配置为在第二时间段内接收到由所 述加密端发送的加密码字插入成功消息、且在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,向所述加密端发送取消插入加密码字消息。
本发明又提供一种数据处理装置,所述装置包括:
收发模块,配置为获取由解密端发送的第一模式配置信息;
处理模块,配置为在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
所述处理模块,还配置为根据所述第一模式配置信息在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息;
所述收发模块,还配置为向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。
在一实施例中,所述收发模块,还配置为获取在第三时间段内且符合模式ECC校验规则的由所述解密端通过开销总线发送的第一模式配置信息。
在一实施例中,所述收发模块,还配置为通过开销总线向所述解密端发送第一当前通路准备完成消息;获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
在一实施例中,所述收发模块,还配置为获取在第四时间段内且符合第二ECC校验规则的由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
在一实施例中,所述处理模块,还配置为根据所述第一模式配置信息在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入加密码字。
本发明实施例所提供的数据处理方法、装置及计算机存储介质,通过解密端向加密端发送第一模式配置信息;在与所述加密端确认当前通路准 备完成后,根据所述第一模式配置信息配置加解密模式;在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;向所述加密端发送所述第二模式配置信息。如此,本发明实施例能够在OTN网络的数据传输过程中实现多种加解密模式间的不停切换,这样在有效提高OTN数据传输的安全性的基础上,得以保证OTN数据的准确性,进而增强OTN系统的传送性能。
附图说明
图1为本发明数据处理方法实施例一的流程图;
图2为本发明数据处理方法实施例二的流程图;
图3为本发明数据处理方法实施例三的流程图;
图4为本发明数据处理方法的实施例的OTN帧的结构示意图;
图5为本发明数据处理方法实施例的详细的模式切换流程图;
图6为本发明加解密模式间切换的数据处理装置实施例的结构示意图一;
图7为本发明加解密模式间切换的数据处理装置实施例的结构示意图二。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述。
图1为本发明数据处理方法实施例一的流程图;如图1所示,本发明实施例提供的一种数据处理方法可以包括如下步骤:
步骤101:向加密端发送第一模式配置信息。
解密端通过开销总线向OTN数据的开销中插入第一模式配置信息发送给加密端;其中,所述第一模式配置信息包括加解密模式、模式ECC校验 值、预留开销位置。
步骤102:在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式。
解密端判断是否获取到在第一时间段内且符合第一通路ECC校验规则的由所述加密端通过开销总线发送的第一当前通路准备完成消息,如果解密端没有获取到由所述加密端通过开销总线发送的第一当前通路准备完成消息,则返回步骤101;如果解密端获取到了由所述加密端通过开销总线发送的第一当前通路准备完成消息,则解密端向OTN数据的开销中插入第二当前通路准备完成消息,通过所述开销总线将第二当前通路准备完成消息发送给所述加密端。
其中,所述第一当前通路准备完成消息中包含有第一通路ECC校验值;所述第二当前通路准备完成消息中包含有第二通路ECC校验值。
步骤103:在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息。
解密端判断在第二时间段内是否监测到在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字的有效字符,如果解密端在第二时间段内没有监测到所述加密码字的有效字符,则在下一轮OTN帧的帧头复帧号位置开始重新进行监测;如果解密端在第二时间段内监测到了所述加密码字的有效字符,则解密端判断所述加密码字的有效字符是否大于等于预设阈值;若所述加密码字的有效字符大于等于所述预设阈值,比如,在8帧字符内监测到大于等于5个,则确定在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字符合预设条件,这时,解密端在下一轮OTN帧的帧头复帧号位置将所述第一模式配置信息更新为第二模式配置信息;若所述加密码字的有效字符小于所述预设阈值,则解密端从下一轮OTN帧的帧头复帧号位置开始重新进行监测。
解密端在判断所述在当前OTN帧的预留开销位置中插入的加密码字是否符合预设条件的同时,判断是否在第二时间段内接收到由所述加密端发送的加密码字插入成功消息,如果所述加密码字符合预设条件且解密端在第二时间段内接收到由所述加密端发送的加密码字插入成功消息,则向所述加密端发送取消插入加密码字消息;否则,从下一轮OTN帧的帧头复帧号位置开始重新进行判断。
其中,所述加密码字可以设为:在ECB模式下为0x11、在CTR模式下为0x22、在直通模式下为0x33,此处仅为举例说明,应用中可根据实际需要进行设定。
步骤104:向所述加密端发送所述第二模式配置信息。
解密端在将所述第一模式配置信息更新为第二模式配置信息后,将所述第二模式配置信息通过开销总线插入到OTN数据的开销中,发送给加密端。
本发明实施例一提供的数据处理方法,通过解密端向加密端发送第一模式配置信息;所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置;在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;向所述加密端发送所述第二模式配置信息。如此,能够实现在OTN网络的数据传输过程中多种加解密模式间的不停切换,在有效提高OTN数据传输的安全性的基础上,得以保证OTN数据的准确性,进而增强OTN系统的传送性能。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行本发明实施例一所述的数据处理方法。
图2为本发明数据处理方法实施例二的流程图;如图2所示,本发明实施例提供的数据处理方法可以包括如下步骤:
步骤201:获取由解密端发送的第一模式配置信息。
加密端通过开销总线从OTN数据的开销中获取由解密端发送的第一模式配置信息;其中,所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置。
具体的,加密端判断是否在第三时间段内获取到符合模式ECC校验规则的由所述解密端通过开销总线发送的第一模式配置信息,如果获取到了所述第一模式配置信息,则执行步骤202;否则,重新进行判断。
步骤202:在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式。
加密端通过开销总线向OTN数据的开销中插入第一当前通路准备完成消息,发送给解密端;加密端判断是否在第四时间段内获取到符合第二ECC校验规则的由所述解密端通过所述开销总线发送的第二当前通路准备完成消息,如果加密端在第四时间段内获取到了所述第二当前通路准备完成消息,则执行步骤203;否则,返回步骤201。
其中,所述第一当前通路准备完成消息中包含有第一通路ECC校验值;所述第二当前通路准备完成消息中包含有第二通路ECC校验值。
步骤203:根据所述第一模式配置信息在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息,向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。
加密端根据所述第一模式配置信息在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入加密码字,连续插入8帧;完成加密码字插入之后,生成加密码字插入成功消息发送给解密端,直到接收到解密端发 送的取消插入加密码字消息,停止加密码字的插入。
其中,所述加密码字可以设为:在ECB模式下为0x11、在CTR模式下为0x22、在直通模式下为0x33,此处仅为举例说明,应用中可根据实际需要进行设定。
本发明实施例二提供的数据处理方法,通过加密端获取由解密端发送的第一模式配置信息;所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置;在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;根据所述第一模式配置信息在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息,向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。如此,能够实现在OTN网络的数据传输过程中多种加解密模式间的不停切换,在有效提高OTN数据传输的安全性的基础上,得以保证OTN数据的准确性,进而增强OTN系统的传送性能。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行本发明实施例二所述的数据处理方法。
为了更加体现出本发明的目的,在上述实施例的基础上,进一步的举例说明。
图3为本发明数据处理方法实施例三的流程图;如图3所示,本发明实施例提供的数据处理方法可以包括如下步骤:
步骤301:解密端向加密端发送第一模式配置信息。
解密端控制器通过开销总线向OTN数据的开销中插入第一模式配置信息,发送给加密端;所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置。
其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种;
模式ECC校验值是在需要校验的数据中加入校验位来实现的;其中,增加的位的数据为1或者0。
步骤302:加密端判断是否在第三时间段内获取到第一模式配置信息。
加密端启动计时器3,设定计时器3的计时时间为第三时间,比如设定为3s,加密端控制器判断是否在3s的时间内通过开销总线获取到OTN开销中的由解密端发送的第一模式配置信息;如果加密端控制器在3s的时间内没有获取到所述第一模式配置信息,则执行步骤303;如果加密端控制器在3s的时间内获取到了所述第一模式配置信息,则执行步骤304。
步骤303:加密端等待进入下一判断周期。
加密端控制器在3s的时间内没有获取到所述第一模式配置信息时,等待进入下一周期重新进行判断。
步骤304:加密端判断所述第一模式配置信息中的模式ECC校验值是否符合模式ECC校验规则。
加密端控制器在3s的时间内获取到了所述第一模式配置信息时,判断该所述第一模式配置信息中的模式ECC校验值是否符合模式ECC校验规则;如果所述第一模式配置信息中的模式ECC校验值不符合模式ECC校验规则,则执行步骤305;如果所述第一模式配置信息中的模式ECC校验值符合模式ECC校验规则,则执行步骤306;
其中,所述模式ECC校验规则根据设定的ECC校验值与读取的ECC代码进行比较确定。
步骤305:加密端不向解密端发送第一当前通路准备完成消息。
加密端控制器在3s的时间内没有获取到所述第一模式配置信息或获取到的第一模式配置信息中的模式ECC校验值不符合模式ECC校验规则时, 不向所述解密端发送第一当前通路准备完成消息,结束任务进入下一更新周期。
步骤306:加密端向解密端发送第一当前通路准备完成消息。
加密端控制器在第三时间段内获取到第一模式配置信息且所述第一模式配置信息中的模式ECC校验值符合模式ECC校验规则时,通过开销总线向OTN数据的开销中插入所述第一当前通路准备完成消息,发送给解密端;其中,所述第一当前通路准备完成消息中包含有第一通路ECC校验值;
例如,第一当前通路准备完成消息可以为0x31、0x37等,其中,所述第一通路ECC校验值占4位。
步骤307:解密端判断是否在第一时间段内获取到第一当前通路准备完成消息。
解密端控制器启动计时器1,设定计时器1的计时时间为第一时间,比如设定为1s,解密端控制器判断是否在1s的时间内通过开销总线获取到OTN开销中的由加密端发送的第一当前通路准备完成消息;其中,所述第一当前通路准备完成消息中包含有第一通路ECC校验值;如果解密端控制器在1s的时间内没有获取到所述第一当前通路准备完成消息,则执行步骤308;如果解密端控制器在1s的时间内获取到了所述第一当前通路准备完成消息,则执行步骤309。
步骤308:解密端等待进入下一判断周期。
解密端控制器在1s的时间内没有获取到所述第一当前通路准备完成消息时,等待进入下一周期重新进行判断。
步骤309:解密端判断所述第一当前通路准备完成消息中的第一通路ECC校验值是否符合第一通路ECC校验规则。
解密端控制器在1s的时间内获取到了所述第一当前通路准备完成消息时,判断该所述第一当前通路准备完成消息中的第一通路ECC校验值是否 符合第一通路ECC校验规则;如果该所述第一通路ECC校验值不符合第一通路ECC校验规则,则执行步骤310;如果该所述第一通路ECC校验值符合第一通路ECC校验规则,则执行步骤311。
其中,所述第一通路ECC校验规则根据设定的ECC校验值与读取的ECC代码进行比较确定。
步骤310:解密端不向加密端发送第二当前通路准备完成消息。
解密端控制器在1s的时间内没有获取到所述第一当前通路准备完成消息或获取到的第一当前通路准备完成消息中的第一通路ECC校验值不符合第一通路ECC校验规则时,不向所述加密端发送第二当前通路准备完成消息,结束任务进入下一更新周期
步骤311:解密端向加密端发送第二当前通路准备完成消息。
解密端控制器通过开销总线向OTN数据开销中插入第二当前通路准备完成消息;所述第二当前通路准备完成消息中包含有第二通路ECC校验值;
比如,第二当前通路准备完成消息可以为0x41、0x47等,其中,所述第一通路ECC校验值占4位。
步骤312:加密端判断是否在第四时间段内获取到第二当前通路准备完成消息。
加密端控制器启动计时器4,设定计时器4的计时时间为第四时间,比如设定为4s,加密端控制器判断是否在4s的时间内通过开销总线获取到OTN开销中的由解密端发送的第二当前通路准备完成消息;其中,所述第二当前通路准备完成消息中包含有第二通路ECC校验值;
如果加密端控制器在4s的时间内没有获取到所述第二当前通路准备完成消息,则执行步骤313;如果加密端控制器在4s的时间内获取到了所述第二当前通路准备完成消息,则执行步骤314;
步骤313:加密端等待进入下一更新周期。
加密端控制器在4s的时间内没有获取到所述第二当前通路准备完成消息时,结束当前任务等待下一个更新周期的到来重启任务。
步骤314:加密端判断所述第二当前通路准备完成消息中的第二通路ECC校验值是否符合第二通路ECC校验规则。
加密端控制器在4s的时间内获取到了所述第二当前通路准备完成消息时,判断所述第二当前通路准备完成消息中的第二通路ECC校验值是否符合第二通路ECC校验规则;如果该所述第二通路ECC校验值不符合第二通路ECC校验规则,则执行步骤315;如果该所述第二通路ECC校验值符合第二通路ECC校验规则,则执行步骤316。
其中,所述第二通路ECC校验规则根据设定的第二通路ECC校验值与读取的ECC代码进行比较确定。
步骤315:不向加密端配置加解密模式。
加密端控制器没有获取到所述第二当前通路准备完成消息或获取到所述第二当前通路准备完成消息中的第二通路ECC校验值不符合第二通路ECC校验规则时,不向加密端配置加解密模式,结束当前任务等待下一个更新周期的到来重启任务。
步骤316:加密端根据第一模式配置信息配置加解密模式。
加密端控制器在4s的时间内获取到了所述第二当前通路准备完成消息且所述第二当前通路准备完成消息中的第二通路ECC校验值符合第二通路ECC校验规则时,根据获取到的第一模式配置信息向加密端配置加解密模式,完成模式确认;
其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种。
步骤317:加密端向解密端发送释放开销总线通知。
加密端控制器在4s的时间内获取到了所述第二当前通路准备完成消息 且所述第二当前通路准备完成消息中的第二通路ECC校验值符合第二通路ECC校验规则时,加密端释放开销总线,向解密端发送释放开销总线通知。
步骤318:解密端判断是否接收到释放开销总线通知。
解密端在向加密端发送第二当前通路准备完成消息后,判断是否接收到释放开销总线通知;如果解密端没有接收到释放开销总线通知,则执行步骤319;如果解密端接收到了释放开销总线通知,则执行步骤320。
步骤319:解密端继续判断是否接收到释放开销总线通知。
解密端在没有接收到释放开销总线通知时,继续判断是否接收到释放开销总线通知直到接收到释放开销总线通知为止。
步骤320:解密端根据所述第一模式配置信息配置加解密模式。
解密端在接收到加密端发送的释放开销总线通知后,与加密端确认当前通路准备完成,这时,解密端控制器根据所述第一模式配置信息给解密端配置加解密模式,完成模式确认;其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种。
步骤321:加密端在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息。
加密端根据所述第一模式配置信息在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始向所述预留开销位置中连续插入8帧加密码字,完成加密码字的插入之后,生成加密码字插入成功消息。
其中,所述加密码字可以设为:在ECB模式下为0x11、在CTR模式下为0x22、在直通模式下为0x33,此处仅为举例说明,应用中可根据实际需要进行设定。
步骤322:加密端向解密端发送加密码字插入成功消息。
加密端在当前OTN帧的预留开销位置中插入加密码字并生成加密码字插入成功消息后,将加密码字插入成功消息发送给解密端。
步骤323:解密端判断在第二时间段内是否接收到由所述加密端发送的加密码字插入成功消息且监测到所述加密码字符合预设条件。
解密端在完成模式确认以后,启动计时器2,设定计时器2的计时时间为第二时间,比如设定为2s;解密端判断是否在2s的时间段内接收到由所述加密端发送的加密码字插入成功消息,同时监测在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始向所述预留开销位置中插入的加密码字是否符合预设条件;如果解密端在2s的间段内接收到了由所述加密端发送的加密码字插入成功消息且监测到所述加密码字有效字符大于等于所述预设阈值,即符合预设条件,则执行步骤325;否则,执行步骤324。
解密端在执行步骤323的同时执行步骤329至步骤331。
步骤324:解密端不向加密端发送取消插入加密码字消息。
解密端在2s的时间段内没有接收到加密端发送的加密码字插入成功消息,或者解密端没有监测到加密码字或监测到的加密码字有效字符小于所述预设阈值时,解密端不向加密端发送取消插入加密码字消息,等待进入下一更新周期重新进行判断。
步骤325:解密端向加密端发送取消插入加密码字消息。
解密端在第二时间段内,即2s的时间段内接收到由所述加密端发送的加密码字插入成功消息、且在监测到在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始插入的加密码字符合预设条件时,将取消插入加密码字消息发送给加密端。
步骤326:加密端判断是否接收到取消插入加密码字消息。
加密端判断是否接收到由解密端发送的取消插入加密码字消息,如果加密端没有接收到由解密端发送的取消插入加密码字消息,则执行步骤327;如果加密端接收到了由解密端发送的取消插入加密码字消息,则执行步骤328。
步骤327:加密端继续插入加密码字。
加密端在当前OTN帧的预留开销位置中插入加密码字后,如果没有接收到取消插入加密码字消息,则继续插入加密码字。
步骤328:加密端取消加密码字的插入。
加密端在当前OTN帧的预留开销位置中插入加密码字后,如果接收到了由解密端发送的取消插入加密码字消息,则取消加密码字的插入,等待进入下一更新周期的码字插入。
步骤329:解密端判断在第二时间段内是否监测到加密码字且监测到的加密码字是否符合预设条件。
解密端判断是否在2s的时间段内监测到在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始向所述预留开销位置中插入的加密码字;如果解密端在2s的时间段内监测到了所述加密码字,且所述加密码字的有效字符大于等于预设阈值,即符合预设条件,则执行步骤331;否则,执行步骤330。
其中,所述加密码字可设为:在ECB模式下为0x11、在CTR模式下为0x22、在直通模式下为0x33,此处仅为举例说明,应用中可根据实际需要进行设定。
步骤330:解密端不将所述第一模式配置信息更新为第二模式配置信息。
解密端从当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始,在2s的时间段内没有监测到所述加密码字,或者监测到所述加密码字的有效字符小于所述预设阈值,即不符合所述预设条件时,解密端不会将所述第一模式配置信息更新为第二模式配置信息,而从下一轮的OTN帧的帧头复帧号MFAS[2:0]=0的位置开始重新进行监测。
步骤331:解密端将所述第一模式配置信息更新为第二模式配置信息。
解密端在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件,即监测到在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始的加密码字的有效字符大于等于预设阈值时,将所述第一模式配置信息更新为第二模式配置信息,即完成模式切换;其中,所述第二模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置。
比如,加密端在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始连续插入了8帧加密码字,设定所述预设阈值为5帧,当解密端从当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始监测8帧加密码字,当监测到的加密码字的有效字符大于等于5帧时,解密端将所述第一模式配置信息更新为第二模式配置信息,完成模式的切换。
为了更加清楚地对本发明数据处理方法的实施例三进行说明,进一步地对加密码字的插入和加密码字的监测作详细地描述。
图4为本发明数据处理方法的实施例的OTN帧的结构示意图;如图4所示,OTN帧主要由预留开销部分和光通路净荷单元k(Optical Channel Payload Unit-k,OPUk)部分组成;
OTN的预留开销是提供给用户传送一些特定需求的字段,比如监测消息的字段;包括光转发单元(Optical Transform Unit,OTU)开销、光通道数据单元(Optical Channel Data Unit,ODU)开销、光通路净荷单元(Optical Channel Payload Unit,OPU)开销和为将来国际标准预留(Reserved for future international standardization,RES)开销。
OTN帧的每个预留开销占用一个字节,在本发明中,模式确认使用一个预留的开销位置OTU开销来完成模式确认;加密码字的插入和加密码字的监测使用RES开销位置来传递加密码字;模式切换中使用和模式确认同一个开销位置来传递码字插入成功信息、码字监测成功信息和取消插入码字信息,即OTU开销。
需要说明的是,本发明仅对OTN帧的光通路净荷单元k部分进行加密,对开销部分不进行加密。
图5为本发明数据处理方法实施例的详细的模式切换流程图;如图5所示,加密端和解密端完成模式确认后,开始进行加密和解密操作。
加密端在模式确认完成以后,在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置连续发送8帧加密码字,插入到OTN开销中;加密端则在下一轮,即图5中所述第二轮OTN帧的帧头复帧号MFAS[2:0]=0的位置开始启用新的模式进行加密,实现加密端的模式切换;如图5所示的8帧数据是都插入加密码字的8帧数据,每个码字占用1个字节,并规定ECB模式下的加密码字为0x11、CTR模式下加密码字为0x22、直通模式下加密码字为0x33。
解密端在模式确认完成以后,在当前OTN帧的帧头复帧号MFAS[2:0]=0的位置开始监测对应的OTN帧开销中的加密码字,如果解密端连续监测到大于等于5帧的有效加密码字,则根据码字的值在下一轮,即图5中所述第二轮OTN帧的帧头复帧号MFAS[2:0]=0的位置启用新的模式进行解密,实现解密端的模式切换。
由于OTN帧协议规定每帧OTN数据对应开销的复帧号MFAS[2:0]的固定填充为0~7,因此,本发明用此开销来确定开始使用新的加解密模式的加密帧号和解密帧号,保证了加密和解密的位置是相同的,从而达到了无损切换的效果,保证了数据的准确性。
本发明实施例三提供的数据处理方法,通过解密端向加密端发送第一模式配置信息;加密端判断是否在第三时间段内获取到第一模式配置信息;加密端在获取到第一模式配置信息后判断所述第一模式配置信息中的模式ECC校验值是否符合模式ECC校验规则;加密端在所述模式ECC校验值符合模式ECC校验规则时向所述解密端发送第一当前通路准备完成消息; 解密端判断是否在第一时间段内获取到第一当前通路准备完成消息;解密端在获取到第一当前通路准备完成消息后判断所述第一当前通路准备完成消息中的第一通路ECC校验值是否符合第一通路ECC校验规则;解密端在第一通路ECC校验值符合第一通路ECC校验规则时向加密端发送第二当前通路准备完成消息;加密端判断是否在第四时间段内获取到第二当前通路准备完成消息;加密端在获取到第二当前通路准备完成消息时,判断所述第二当前通路准备完成消息中的第二通路ECC校验值是否符合第二通路ECC校验规则;加密端在第二通路ECC校验值符合第二通路ECC校验规则时,根据第一模式配置信息配置加解密模式;解密端判断是否接收到释放开销总线通知;解密端在接收到释放开销总线通知时,根据所述第一模式配置信息配置加解密模式;加密端在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息;加密端向解密端发送加密码字插入成功消息;解密端判断在第二时间段内是否接收到由所述加密端发送的加密码字插入成功消息且监测到所述加密码字符合预设条件;解密端在第二时间段内接收到了所述加密码字插入成功消息且监测到所述加密码字符合预设条件时,向加密端发送取消插入加密码字消息;加密端判断是否接收到取消插入加密码字消息;加密端在接收到取消插入加密码字消息后,取消加密码字的插入;同时,解密端判断在第二时间段内是否监测到加密码字且监测到的加密码字是否符合预设条件;解密端在第二时间段内监测到加密码字且监测到的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息。如此,本发明实施例能够实现在OTN网络的数据传输过程中多种加解密模式间的不停切换,在有效提高OTN数据传输的安全性的基础上,得以保证OTN数据的准确性,进而增强OTN系统的传送性能。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存 储有计算机可执行指令,所述计算机可执行指令用于执行本发明实施例所述的数据处理方法。
图6为本发明加解密模式间切换的数据处理装置实施例的结构示意图;如图6所示,本发明实施例提供的加解密模式间切换的数据处理装置06包括:收发模块61、处理模块62、更新模块63;其中,
所述收发模块61,配置为向加密端发送第一模式配置信息;所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置;
其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种;
所述处理模块62,配置为在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
所述更新模块63,配置为在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;
所述收发模块61,还配置为向所述加密端发送所述第二模式配置信息。
在一实施例中,所述收发模块61,还配置为获取由所述加密端通过开销总线发送的第一当前通路准备完成消息;所述第一当前通路准备完成消息中包含有第一通路ECC校验值;通过所述开销总线向所述解密端发送第二当前通路准备完成消息;所述第二当前通路准备完成消息中包含有第二通路ECC校验值。
在一实施例中,所述收发模块61,还配置为获取在第一时间段内且符合第一通路ECC校验规则的由所述加密端通过所述开销总线发送的第一当前通路准备完成消息。
在一实施例中,所述数据处理装置06还包括:判断模块64;其中,
判断模块64,配置为在第二时间段内监测到在当前OTN帧的帧头复帧 号位置开始向所述预留开销位置中插入的加密码字的有效字符是否大于等于预设阈值,若所述加密码字的有效字符大于等于所述预设阈值,则确定在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字符合预设条件;
其中,所述加密码字在ECB模式下可以为0x11、在CTR模式下可以为0x22、在直通模式下可以为0x33,也可以设置为其他代码,此处不加以限定。
在一实施例中,所述收发模块61,还配置为在第二时间段内接收到由所述加密端发送的加密码字插入成功消息、且在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,向所述加密端发送取消插入加密码字消息。
本实施例的装置,可以用于执行上述所示方法实施例的技术方案,其实现原理和技术效果类似,此处不再赘述。
在实际应用中,所述收发模块61、处理模块62、更新模块63、判断模块64均可由位于加解密模式间切换的数据处理装置06中的中央处理器(Central Processing Unit,CPU)、微处理器(Micro Processor Unit,MPU)、数字信号处理器(Digital Signal Processor,DSP)或现场可编程门阵列(Field Programmable Gate Array,FPGA)等实现。
图7为本发明加解密模式间切换的数据处理装置实施例的结构示意图;如图7所示,本发明实施例提供的加解密模式间切换的数据处理装置07包括:收发模块71、处理模块72;其中,
所述收发模块71,配置为获取由解密端发送的第一模式配置信息;所述第一模式配置信息包括:加解密模式、模式ECC校验值、预留开销位置;
其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种
所述处理模块72,配置为在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
所述处理模块72,还配置为根据所述第一模式配置信息在当前OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息;
所述收发模块71,还配置为向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。
在一实施例中,所述收发模块71,还配置为获取在第三时间段内且符合模式ECC校验规则的由所述解密端通过开销总线发送的第一模式配置信息。
在一实施例中,所述收发模块71,配置为通过开销总线向所述解密端发送第一当前通路准备完成消息;所述第一当前通路准备完成消息中包含有第一通路ECC校验值;获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息;所述第二当前通路准备完成消息中包含有第二通路ECC校验值。
在一实施例中,所述收发模块71,还配置为获取在第四时间段内且符合第二ECC校验规则的由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
所述处理模块72,还配置为根据所述第一模式配置信息在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入加密码字。
其中,所述加密码字在ECB模式下可以为0x11、在CTR模式下可以为0x22、在直通模式下可以为0x33,也可以设置为其他代码,此处不加以限定。
本实施例的装置,可以用于执行上述所示方法实施例的技术方案,其实现原理和技术效果类似,此处不再赘述。
在实际应用中,所述收发模块71、处理模块72均可由位于加解密模式 间切换的数据处理装置07中的CPU、MPU、DSP或FPGA等实现。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用硬件实施例、软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
以上所述,仅为本发明的较佳实施例而已,并非用于限定本发明的保护范围。
工业实用性
本发明实施例所述数据处理方法,通过解密端向加密端发送第一模式配置信息;在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;向所述加密端发送所述第二模式配置信息。如此,能够在OTN网络的数据传输过程中实现多种加解密模式间的不停切换,在有效提高OTN数据传输的安全性的基础上,得以保证OTN数据的准确性,进而增强OTN系统的传送性能。

Claims (26)

  1. 一种数据处理方法,所述方法包括:
    向加密端发送第一模式配置信息;
    在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
    在监测到在当前光传送网OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;
    向所述加密端发送所述第二模式配置信息。
  2. 根据权利要求1所述的方法,其中,所述在与所述加密端确认当前通路准备完成,包括:
    获取由所述加密端通过开销总线发送的第一当前通路准备完成消息;
    通过所述开销总线向所述加密端发送第二当前通路准备完成消息。
  3. 根据权利要求2所述的方法,其中,所述获取由所述加密端通过所述开销总线发送的第一当前通路准备完成消息,包括:
    获取在第一时间段内且符合第一通路ECC校验规则的由所述加密端通过所述开销总线发送的第一当前通路准备完成消息。
  4. 根据权利要求1所述的方法,其中,所述监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件,包括:
    在第二时间段内监测到在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字的有效字符是否大于等于预设阈值,若所述加密码字的有效字符大于等于所述预设阈值,则确定在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字符合预设条件。
  5. 根据权利要求1所述的方法,其中,所述方法还包括:
    在第二时间段内接收到由所述加密端发送的加密码字插入成功消息、且在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件 时,向所述加密端发送取消插入加密码字消息。
  6. 根据权利要求1至5任一项所述的方法,其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种。
  7. 一种数据处理方法,所述方法包括:
    获取由解密端发送的第一模式配置信息;
    在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
    根据所述第一模式配置信息在当前光传送网OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息,向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。
  8. 根据权利要求7所述的方法,其中,所述获取由解密端发送的第一模式配置信息,包括:
    获取在第三时间段内且符合模式ECC校验规则的由所述解密端通过开销总线发送的第一模式配置信息。
  9. 根据权利要求7所述的方法,其中,所述在与所述解密端确认当前通路准备完成,包括:
    通过开销总线向所述解密端发送第一当前通路准备完成消息;
    获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
  10. 根据权利要求9所述的方法,其中,所述获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息,包括:
    获取在第四时间段内且符合第二ECC校验规则的由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
  11. 根据权利要求7所述的方法,其中,所述根据所述第一模式配置 信息在当前OTN帧的预留开销位置中插入加密码字,包括:
    根据所述第一模式配置信息在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入加密码字。
  12. 根据权利要求7至11任一项所述的方法,其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种。
  13. 一种数据处理装置,所述数据处理装置包括:
    收发模块,配置为向加密端发送第一模式配置信息;
    处理模块,配置为在与所述加密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
    更新模块,配置为在监测到在当前光传送网OTN帧的预留开销位置中插入的加密码字符合预设条件时,将所述第一模式配置信息更新为第二模式配置信息;
    所述收发模块,还配置为向所述加密端发送所述第二模式配置信息。
  14. 根据权利要求13所述的装置,其中,
    所述收发模块,还配置为获取由所述加密端通过开销总线发送的第一当前通路准备完成消息;通过所述开销总线向所述解密端发送第二当前通路准备完成消息。
  15. 根据权利要求14所述的装置,其中,
    所述收发模块,还配置为获取在第一时间段内且符合第一通路ECC校验规则的由所述加密端通过所述开销总线发送的第一当前通路准备完成消息。
  16. 根据权利要求13所述的装置,其中,所述数据处理装置还包括:
    判断模块,配置为在第二时间段内监测到在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字的有效字符是否大于等于预设阈值,若所述加密码字的有效字符大于等于所述预设阈值,则确定在 当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入的加密码字符合预设条件。
  17. 根据权利要求13所述的装置,其中,
    所述收发模块,还配置为在第二时间段内接收到由所述加密端发送的加密码字插入成功消息、且在监测到在当前OTN帧的预留开销位置中插入的加密码字符合预设条件时,向所述加密端发送取消插入加密码字消息。
  18. 根据权利要求13至17任一项所述的装置,其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种。
  19. 一种数据处理装置,所述数据处理装置包括:
    收发模块,配置为获取由解密端发送的第一模式配置信息;
    处理模块,配置为在与所述解密端确认当前通路准备完成后,根据所述第一模式配置信息配置加解密模式;
    所述处理模块,还配置为根据所述第一模式配置信息在当前光传送网OTN帧的预留开销位置中插入加密码字,并生成加密码字插入成功消息;
    所述收发模块,还配置为向所述解密端发送所述加密码字插入成功消息,直到接收到由所述解密端发送的取消插入加密码字消息为止。
  20. 根据权利要求19所述的装置,其中,
    所述收发模块,还配置为获取在第三时间段内且符合模式ECC校验规则的由所述解密端通过开销总线发送的第一模式配置信息。
  21. 根据权利要求19所述的装置,其中,
    所述收发模块,还配置为通过开销总线向所述解密端发送第一当前通路准备完成消息;获取由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
  22. 根据权利要求21所述的装置,其中,
    所述收发模块,还配置为获取在第四时间段内且符合第二ECC校验规 则的由所述解密端通过所述开销总线发送的第二当前通路准备完成消息。
  23. 根据权利要求19所述的装置,其中,
    所述处理模块,还配置为根据所述第一模式配置信息在当前OTN帧的帧头复帧号位置开始向所述预留开销位置中插入加密码字。
  24. 根据权利要求19至23任一项所述的装置,其中,所述加解密模式为电话本ECB模式、计数器CTR模式、直通模式中的任意一种。
  25. 一种计算机存储介质,所述计算机存储介质中存储有可执行指令,所述可执行指令用于执行权利要求1至6任一项所述的数据处理方法。
  26. 一种计算机存储介质,所述计算机存储介质中存储有可执行指令,所述可执行指令用于执行权利要求7至12任一项所述的数据处理方法。
PCT/CN2017/082632 2016-08-31 2017-04-28 数据处理方法、装置及计算机存储介质 WO2018040605A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610796432.7 2016-08-31
CN201610796432.7A CN107800502B (zh) 2016-08-31 2016-08-31 加解密模式间切换的方法及装置

Publications (1)

Publication Number Publication Date
WO2018040605A1 true WO2018040605A1 (zh) 2018-03-08

Family

ID=61299974

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/082632 WO2018040605A1 (zh) 2016-08-31 2017-04-28 数据处理方法、装置及计算机存储介质

Country Status (2)

Country Link
CN (1) CN107800502B (zh)
WO (1) WO2018040605A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112351422A (zh) * 2020-09-11 2021-02-09 深圳Tcl新技术有限公司 加解密数据的方法、装置、设备及计算机存储介质

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112929324B (zh) * 2019-12-06 2023-02-21 中兴通讯股份有限公司 一种加密与非加密的切换方法、装置、设备及存储介质
CN113765853A (zh) * 2020-06-03 2021-12-07 中兴通讯股份有限公司 光传送网中加密控制开销传输方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101400059A (zh) * 2007-09-28 2009-04-01 华为技术有限公司 一种active状态下的密钥更新方法和设备
CN103079197A (zh) * 2011-10-25 2013-05-01 中兴通讯股份有限公司 Pws密钥的更新方法及装置
US20140044262A1 (en) * 2012-08-09 2014-02-13 Cisco Technology, Inc. Low Latency Encryption and Authentication in Optical Transport Networks
CN103746814A (zh) * 2014-01-27 2014-04-23 华为技术有限公司 一种加密、解密的方法及设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101400059A (zh) * 2007-09-28 2009-04-01 华为技术有限公司 一种active状态下的密钥更新方法和设备
CN103079197A (zh) * 2011-10-25 2013-05-01 中兴通讯股份有限公司 Pws密钥的更新方法及装置
US20140044262A1 (en) * 2012-08-09 2014-02-13 Cisco Technology, Inc. Low Latency Encryption and Authentication in Optical Transport Networks
CN103746814A (zh) * 2014-01-27 2014-04-23 华为技术有限公司 一种加密、解密的方法及设备

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112351422A (zh) * 2020-09-11 2021-02-09 深圳Tcl新技术有限公司 加解密数据的方法、装置、设备及计算机存储介质
CN112351422B (zh) * 2020-09-11 2024-04-30 深圳Tcl新技术有限公司 加解密数据的方法、装置、设备及计算机存储介质

Also Published As

Publication number Publication date
CN107800502B (zh) 2019-05-31
CN107800502A (zh) 2018-03-13

Similar Documents

Publication Publication Date Title
JP5129887B2 (ja) 高精度時間プロトコルおよび媒体アクセス制御セキュリティをネットワークエレメントに統合するシステム
US11606341B2 (en) Apparatus for use in a can system
US10104047B2 (en) Method and system for encrypting/decrypting payload content of an OTN frame
US10771966B2 (en) Encryption method, decryption method, and related apparatus
JP4603043B2 (ja) シンクml同期データを送信するための方法
JP6617173B2 (ja) 複数のマネージャまたはアクセスポイントを有する無線ネットワークにおける独立したセキュリティ
CN112688845B (zh) 车载can网络的通信方法及装置
US9509414B2 (en) Encryption and decryption method and device
WO2017088565A1 (zh) 一种加密解密方法、加密解密装置及数据传输系统
KR102017758B1 (ko) 의료 기기, 게이트웨이 기기 및 이를 이용한 프로토콜 보안 방법
WO2021244489A1 (zh) 光传送网中加密控制开销传输方法及装置
WO2018040605A1 (zh) 数据处理方法、装置及计算机存储介质
CN102347831B (zh) 时间消息处理方法、装置及系统
US9705671B2 (en) One-way key switching method and implementation device
CN103595527B (zh) 一种双向密钥的切换方法及实现装置
WO2011023010A1 (zh) 一种用于伪线网络的数据安全发送接收方法、装置及系统
CN109120608B (zh) 一种防重放安全通讯处理方法及装置
WO2016184238A1 (zh) 一种基于光传输网otn的密钥更新的方法、装置和系统
KR102400940B1 (ko) 자율 주행 차량의 통신 보안 장치 및 방법
CN108141358B (zh) 用于在电路装置中产生密钥的方法
CN113709069B (zh) 一种数据传输的无损切换方法及装置
CN117499146A (zh) 面向fc与以太网协议转换的加密通信方法、装置和系统
JP5465335B2 (ja) 通信システム、通信制御装置、送信装置、受信装置および通信制御方法
CN116599668A (zh) 变更加密协议的方法及装置、存储介质及电子设备
CN117220914A (zh) 加解密方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17844913

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17844913

Country of ref document: EP

Kind code of ref document: A1