首页|基于零信任机制的工业互联网边界防护方案研究

基于零信任机制的工业互联网边界防护方案研究

扫码查看
随着互联网和信息技术的快速发展,传统的工业制造与新兴信息技术、互联网技术开始互相融合,"工业互联网"逐渐崭露头角,并广泛应用于能源、电力、交通、军工、航空航天、医疗等关系到国家安全、国计民生的重要行业。工业互联网涉及到众多国家关键基础设施,因此工业互联网的安全将影响到社会安全、公众安全甚至国家安全。该文对工业互联网中存在的网络安全风险进行分析,并提出一种基于"零信任"机制的边界防护方案,在兼容数量庞大、种类繁多的工业设备、操作系统以及生产应用的同时,为整个生产内网提供整体安全防护能力。基于零信任机制的工业互联网边界防护方案区别于传统防护思路,以白名单机制代替黑名单机制,以应用隐身代替技术对抗,以动态验证代替静态检测。最后,给出了基于零信任机制实现的工业互联网边界防护应用案例,并结合系统功能分析了该方案的技术优势。
Research on Border Protection Scheme of Industrial Internet Based on Zero Trust Mechanism
With the rapid development of the Internet and information technology,traditional industrial manufacturing has begun to integrate with emerging information technology and internet technology.The"Industrial Internet"has gradually emerged and is widely used in important industries related to national security,national economy,and people's livelihood,such as energy,electricity,transportation,military industry,aerospace,and healthcare.The industrial internet involves many key infrastructure in countries,so its security will affect social security,public security,and even national security.We analyze the network security risks in the industrial internet and propose a boundary protection scheme based on the"zero trust"mechanism,which provides overall security protection capabilities for the entire production intranet while being compatible with a large number and variety of industrial equipment,operating systems,and production applications.The industrial internet boundary protection scheme based on zero trust mechanism is different from traditional protection ideas,using whitelist mechanism instead of blacklist mechanism,applying stealth instead of technical confrontation,and dynamic verification instead of static detection.Finally,we present an application case of industrial internet boundary protection based on zero trust mechanism,and analyze the technical advantages of this solution in combination with system functions.

Industrial Internetzero trustboundary protectioncritical information infrastructurewhitelist mechanism

王奕钧

展开 >

公安部第一研究所,北京 100048

工业互联网 零信任 边界防护 关键信息基础设施 白名单机制

国家重点研发计划项目

2020YFB1806500

2024

计算机技术与发展
陕西省计算机学会

计算机技术与发展

CSTPCD
影响因子:0.621
ISSN:1673-629X
年,卷(期):2024.34(3)
  • 18