基于零信任的省级气象信息网络防护技术研究  

Research on Provincial Meteorological Information Network Protection Technology Based on Zero Trust

在线阅读下载全文

作  者:刘晓波 冯冼 张思睿 郑秋生 周武宁 LIU Xiaobo;FENG Xian;ZHANG Sirui;ZHENG Qiusheng;ZHOU Wuning(Hunan Meteorological Information Center,Changsha,Hunan 410118,China;Hunan Primary Laboratory of Meteorological Disaster Prevention and Reduction,Changsha,Hunan 410118,China;Qi-Anxin Science and Technology Group Co.,Ltd.,Changsha,Hunan 410000,China)

机构地区:[1]湖南省气象信息中心,湖南长沙410118 [2]气象防灾减灾湖南省重点实验室,湖南长沙410118 [3]奇安信科技集团股份有限公司,湖南长沙410000

出  处:《计算技术与自动化》2024年第2期151-155,共5页Computing Technology and Automation

摘  要:随着省级气象部门对外服务统一出口要求,系统和数据逐步集约化,部分省级单位建立了专门对外提供数据服务的数据中台,传统网络安全技术在当前新的业务形态和场景下显得捉襟见肘。零信任作为一种全新的网络安全理念,为重构网络安全架构提供了理论指引。设计了一种基于零信任的适用于省级气象部门的安全架构体系,并基于零信任构建了气象网络的可信访问通道解决数据访问管道安全问题,提出了一种数据动态授权访问的方法解决气象数据安全访问授信问题,给出终端可信空间方案解决端上数据泄露问题。With the unified export requirements for external services of provincial meteorological departments,the system and data are gradually intensified,and some provincial units have established data centers dedicated to providing external data services,and traditional network security technology is strained under the current new business forms and scenarios.As a new concept of network security,zero trust provides theoretical guidance for reconstructing network security architecture.This paper designs a zero-trust-based security architecture applicable to provincial meteorological departments,constructs a trusted access channel of meteorological network based on zero-trust to solve the security problem of data access pipeline,proposes a method of dynamic data authorization access to solve the problem of meteorological data security access credit,and proposes a terminal trusted space scheme to solve the data leakage problem on the terminal.

关 键 词:零信任模型 动态授权 可信访问通道 可信终端空间 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象