Performance Evaluation of Algorithmic Support for Secure One-Way Communications in Geographically Distributed Organizations
Abstract
Implementation of hardware-based unidirectional security gateways (data diodes) in Critical Energy Infrastructures (CEI) results in a significant cryptographic synchronization and reliability dilemma. Conventional network transport protocols and interactive key agreement procedures suffer from complete algorithm failure due to breaking the feedback loop and thus resulting in retransmission flooding, buffer bloating, or catastrophic packet fragmentation in case of aggressive industrial noise. In this work, we provide a thorough performance analysis of a single, non-interactive security infrastructure dedicated to unbuffered, no feedback channels in geographically distributed entities. The analyzed infrastructure consists of Temporal Identity-Based Initialization (TIBI) procedure for autonomous spatiotemporal key synchronization, Lightweight Hybrid Encapsulation with Adaptive Forward Error Correction (LHE-FEC) through Systematic Random Linear Network Coding (S-RLNC) for lossless delivery at arbitrary data rates, and Interleaved Merkle-Hash Chains (IM-Forest) for asynchronous data integrity verification. Using discrete event simulation experiments of up to 1,000 concurrently connected industrial nodes, we show that the proposed architecture is able to demonstrate near linear latency scaling (~450 ms at maximum scale), as well as 100% payload reconstruction under aggressive burst loss scenarios up to 30%. In addition, the computational burden assessment demonstrates that there is an operational asymmetry of more than 95%, which successfully manages to outsource computationally intensive processes such as matrix inversion and recursive hashing to processing authorities and maintain the battery and processing efficiency of the periphery devices.