Annotation A method of ensuring the integrity of data transmitted over communication channels of VPNs of large-scale information systems functioning in the conditions of the destructive influence of the attacker is considered. The proposed method allows to recover data packets subjected to erasure and imitation. The purpose of the research is to increase the stability of data transmission over VPN communication channels by implementing the procedure for recovering erased IP-packets and increasing the level of imitation security of the transmitted data. Research methods: aggregation of methods of cryptographic control of data integrity and methods of redundant coding of data, application of methods of the theory of Markov random processes to determine the probability of providing satisfactory support for applications in conditions of destructive influence of an attacker with various parameters. Research results: analysis of the object of research – VPN of large-scale information systems was carried out. It leads to the conclusion about the need to protect data transmitted through such communication channels for the implementation of national strategies for economic development. A mathematical model of the functioning of a data transmission system over a VPN communication channel under the conditions of a destructive influence of an attacker is presented. A method is proposed to ensure the integrity of transmitted data based on an original scheme for sharing known solutions, generating a synergistic effect. The method allows recovering dmin −1 erased data packets. The proposed solution makes it possible to increase the stability and speed of data transmission over the communication channels of the network in the conditions of the destructive influence of the attacker and the imitation of data by the attacker.
Read full abstract