检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:孟斌[1] Meng Bin(School of Economics and Management,Beijing University of Posts and Telecommunications,Beijing 100876)
机构地区:[1]北京邮电大学经济管理学院
出 处:《信息安全研究》2019年第6期521-527,共7页Journal of Information Security Research
摘 要:党政机关电子公文系统是处理、流转、存储我国政务办公电子文件的重要应用系统,保障数据安全是实现其安全可靠的基本内容.分析了电子公文系统3个关键数据交互过程中的主要安全风险,并分别提出基于密码技术的典型安全保障机制.特别针对数据管理过程中的防泄密难点,创新性地提出“防内不防外”的信息保护方案思路,重点针对内部管理人员的数据安全风险,将授权与加密机制相结合,实现“一文一密”的细粒度管控.最后以电子公文传输系统应用场景为例,阐述了该方案保护电子文件类数据安全的机理和效果.The electronic official document system of the party and government institutions is an important application system for processing, transferring and storing electronic files of government offices in China, and data security is the basic content for realizing its security and reliability. This paper analyzes the main security risks in the three key data interaction processes of the electronic document system, and proposes a typical security guarantee mechanism based on cryptography. Especially for the difficulty of anti-leakage in the data management process, this paper innovatively puts forward the data security encryption idea of "internal risk more important than external risk", focus on the risk of internal management personnel, and combines authorization and encryption mechanism to achieve "one document and one secret". Finally, taking the application scenario of the electronic document transmission system as an example, the mechanism and effect of the scheme to protect the data security of electronic records are expounded.
关 键 词:电子公文系统 数据安全 密码技术 内部管理 电子文件
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.28