Page 397 - 《软件学报》2026年第4期
P. 397
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(4):1838−1853 [doi: 10.13328/j.cnki.jos.007485] [CSTR: 32375.14.jos.007485] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
基于真实源地址验证的轻量共识机制
徐 易 1 , 陈熠豪 2 , 王晓亮 3 , 徐 恪 2 , 李 琦 1
1
(清华大学 网络科学与网络空间研究院, 北京 100084)
2
(清华大学 计算机科学与技术系, 北京 100084)
3
(首都师范大学 信息工程学院, 北京 100048)
通信作者: 李琦, E-mail: qli01@tsinghua.edu.cn
摘 要: 近年来, 许多研究提出利用共识机制增强网络层安全性. 然而, 现有共识机制存在密钥维护数量多、信任
关系传递不灵活和节点身份验证开销大等局限, 难以满足网络层功能的性能需求. 为解决这些问题, 提出一种基于
真实源地址验证技术的轻量共识框架. 该框架在多个层次上优化共识效率: 首先, 针对同一地址域内的共识节点,
该框架利用真实地址作为身份识别标志, 通过域内节点共享同一密钥的方式实现密钥聚合, 从而大幅降低所需维
护的密钥数量; 其次, 在地址域的粒度上, 该框架构建以真实地址为信任基础的网络信任联盟, 基于前缀树聚合可
信地址域, 从而在实现灵活信任传递的同时, 进一步降低所需维护的密钥数量; 最后, 在节点层面, 针对传统共识节
点身份验证开销大的问题, 该框架设计基于真实地址和对称密钥的分步验证机制, 从而有效降低共识开销, 实现共
识过程轻量化. 仿真实验结果表明, 所提出的轻量共识框架与基于 ECDSA 身份验证的共识机制相比, 平均可提升
70% 共识吞吐量并降低 40% 共识计算开销, 显著提升了共识效率.
关键词: 真实源地址验证; 共识机制; 网络层安全
中图法分类号: TP393
中文引用格式: 徐易, 陈熠豪, 王晓亮, 徐恪, 李琦. 基于真实源地址验证的轻量共识机制. 软件学报, 2026, 37(4): 1838–1853. http://
www.jos.org.cn/1000-9825/7485.htm
英文引用格式: Xu Y, Chen YH, Wang XL, Xu K, Li Q. Lightweight Consensus Mechanism Based on Source Address Validation.
Ruan Jian Xue Bao/Journal of Software, 2026, 37(4): 1838–1853 (in Chinese). http://www.jos.org.cn/1000-9825/7485.htm
Lightweight Consensus Mechanism Based on Source Address Validation
1 2 3 2 1
XU Yi , CHEN Yi-Hao , WANG Xiao-Liang , XU Ke , LI Qi
1
(Institute for Network Sciences and Cyberspace, Tsinghua University, Beijing 100084, China)
2
(Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China)
3
(Information Engineering College, Capital Normal University, Beijing 100048, China)
Abstract: In recent years, many studies have proposed using consensus mechanisms to enhance network layer security. However, existing
consensus mechanisms have limitations, such as heavy key maintenance, inflexible trust expansion, and high authentication overhead. To
address these issues, this study proposes a lightweight consensus framework based on source address validation. The framework optimizes
consensus efficiency at multiple levels: First, among consensus nodes within the same domain, the framework uses authentic IP addresses
as identities and achieves key aggregation by sharing the same key among nodes within the domain, thus efficiently reducing the number
of keys that need to be maintained. Second, at the domain level, the framework constructs a trusted network alliance based on trust
derived from authentic IP addresses and aggregates trusted domains through a prefix tree, thus further reducing the number of keys to
maintain while enabling flexible trust expansion. Finally, at the node level, to address the issue of high authentication overhead, the
framework designs a two-step authentication mechanism based on authentic IP addresses and symmetric keys, effectively reducing
* 基金项目: 国家自然科学基金 (62132011)
收稿时间: 2024-12-24; 修改时间: 2025-02-06; 采用时间: 2025-06-09; jos 在线出版时间: 2025-11-05
CNKI 网络首发时间: 2025-11-06

