查看更多>>摘要:With the rapid development of cloud manufacturing technology and the new generation of artificial intelligence tech-nology,the new cloud manufacturing system(NCMS)built on the connotation of cloud manufacturing 3.0 presents a new busi-ness model of"Internet of everything,intelligent leading,data driving,shared services,cross-border integration,and universal innovation".The network boundaries are becoming increasingly blurred,NCMS is facing security risks such as equipment unau-thorized use,account theft,static and extensive access control policies,unauthorized access,supply chain attacks,sensitive data leaks,and industrial control vulnerability attacks.Tradi-tional security architectures mainly use information security technology,which cannot meet the active security protection requirements of NCMS.In order to solve the above problems,this paper proposes an integrated cloud-edge-terminal security system architecture of NCMS.It adopts the zero trust concept and effectively integrates multiple security capabilities such as network,equipment,cloud computing environment,application,identity,and data.It adopts a new access control mode of"con-tinuous verification+dynamic authorization",classified access control mechanisms such as attribute-based access control,role-based access control,policy-based access control,and a new data security protection system based on blockchain,achieving"trustworthy subject identity,controllable access behavior,and effective protection of subject and object resources".This archi-tecture provides an active security protection method for NCMS in the digital transformation of large enterprises,and can effec-tively enhance network security protection capabilities and cope with increasingly severe network security situations.