首页|基于零信任的省级气象信息网络防护技术研究

基于零信任的省级气象信息网络防护技术研究

Research on Provincial Meteorological Information Network Protection Technology Based on Zero Trust

扫码查看
随着省级气象部门对外服务统一出口要求,系统和数据逐步集约化,部分省级单位建立了专门对外提供数据服务的数据中台,传统网络安全技术在当前新的业务形态和场景下显得捉襟见肘.零信任作为一种全新的网络安全理念,为重构网络安全架构提供了理论指引.设计了一种基于零信任的适用于省级气象部门的安全架构体系,并基于零信任构建了气象网络的可信访问通道解决数据访问管道安全问题,提出了一种数据动态授权访问的方法解决气象数据安全访问授信问题,给出终端可信空间方案解决端上数据泄露问题.
With the unified export requirements for external services of provincial meteorological departments,the sys-tem and data are gradually intensified,and some provincial units have established data centers dedicated to providing external data services,and traditional network security technology is strained under the current new business forms and scenarios.As a new concept of network security,zero trust provides theoretical guidance for reconstructing network security architecture.This paper designs a zero-trust-based security architecture applicable to provincial meteorological departments,constructs a trusted access channel of meteorological network based on zero-trust to solve the security problem of data access pipeline,proposes a method of dynamic data authorization access to solve the problem of meteorological data security access credit,and proposes a terminal trusted space scheme to solve the data leakage problem on the terminal.

zero trust modeldynamic authorizationtrusted access channeltrusted terminal space

刘晓波、冯冼、张思睿、郑秋生、周武宁

展开 >

湖南省气象信息中心,湖南 长沙 410118

气象防灾减灾湖南省重点实验室,湖南 长沙 410118

奇安信科技集团股份有限公司,湖南 长沙 410000

零信任模型 动态授权 可信访问通道 可信终端空间

2024

计算技术与自动化
湖南大学

计算技术与自动化

CSTPCD
影响因子:0.295
ISSN:1003-6199
年,卷(期):2024.43(2)