检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:蒋驰 李国风 马帅 Jiang Chi;Li Guofeng;Ma Shuai(Mingyang Industrial Technology Research Institute(Shenyang)Co.,Ltd.,Shengyang Liaoning,110000)
机构地区:[1]明阳产业技术研究院(沈阳)有限公司,辽宁沈阳110000
出 处:《工业信息安全》2024年第1期41-51,共11页Industry Information Security
摘 要:本文介绍了国内外零信任安全新型网络安全架构研究与应用情况,重点阐述了典型工业企业IPv6安全自组织网络解决方案的技术架构、产品组成、部署实施路径以及方案的应用成效。IPv6安全自组织网络贯彻“零信任安全”理念,基于自主研发的IPv6密码标识体系,系统性整合零信任网络访问(ZTNA)、软件定义边界(SDP)、网络微隔离(MSG)技术,实现双向鉴权、加密通信、端一端防护的Overlay网络架构。IPv6安全自组织网络采用以“用户为中心”的模式,构建安全、私密、易于管理的覆盖网络(Overlay),可在当前及未来的泛在网络环境中,形成跨越几乎任何设备、网络或环境的专属互联网络,可为工业行业构建IT/OT融合网络创新安全范式,提供一体化安全与组网解决方案,解决工业企业网络管理和运营中的多个关键问题。This paper introduces the research and application of zero-trust security new network security architecture at home and abroad,and focuses on the technical architecture,product composition,deployment and implementation path and the application effect of the typical IPv6 security Ad-Hoc network solution for industrial enterprises.The IPv6 security Ad-Hoc network implements the concept of"zero-trust security"and systematically integrates zero-trust network access(ZTNA),software-defined boundary(SDP),and network micro-isolation(MSG)technologies based on the self-developed IPv6 cryptographic identity system,which is an overlay network architecture that implements bidirectional authentication,encrypted communication,and end-to-end protection.IPv6 security Ad-Hoc network adopts the"user-centered"mode to build a secure,private,and easy-to-manage overlay network,which can form an exclusive Internet network spanning almost any device,network or environment in the current and future ubiquitous network environment,and can build an innovative security paradigm of IT/OT converged network for industrial industries,and provides integrated security and networking solutions to address multiple critical issues in network management and operation of industrial enterprises.
关 键 词:工业企业 零信任网络 IPv6安全自组织网络 新型企业网络架构 解决方案
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.49