首页|零信任工业无线局域网安全访问框架与机制

零信任工业无线局域网安全访问框架与机制

扫码查看
针对工业无线局域网日益复杂的安全态势,开展了零信任工业无线局域网安全访问技术研究.首先,为了兼容工业网络中不具备扩展性终端,在融合无线局域网安全认证与软件定义边界(SDP)安全接入技术的基础上,提出了兼容传统无线工业终端的零信任工业无线局域网安全访问系统框架,在无线接入点中内嵌SDP透明代理,并适应性地引入了SDP网关与安全控制器;然后,设计了面向SDP与无线网络认证融合的身份体系,以及基于SDP透明代理的服务安全访问机制,同时,为了实现终端访问异常行为动态识别及访问权限动态调整,设计了基于终端访问服务的空间、时间、频率多维的信任评估模型,以及基于信任评估的动态访问控制方法.最后,通过系统实验的方法验证了所提出的系统框架及方法的安全性与有效性.
Secure Access Framework and Mechanism for Zero-Trust Industrial WLAN
In view of the increasingly complex security situation of the industrial wireless LAN,this paper presents a novel zero-trust security access framework and mechanisms for industrial wireless LAN by integrating software-defined perimeter(SDP)secure access and wireless LAN security authentication techniques.First,to support traditional wireless industrial terminals that are difficult to install and update software owing to their relatively closed operating systems,this framework embeds SDP transparent proxies in wireless ac-cess points(APs),and adaptively introduces the SDP gateway and the security controller;then,a unified identity system for the inte-gration of SDP and wireless LAN authentication,and a service security access mechanism based on SDP transparent proxy are de-signed.Additionally,to realize the dynamic identification of abnormal terminal access behaviors and the dynamic adjustment of access strategies,a multi-dimensional trust evaluation model based on the access space,time and frequency of terminal is designed.Finally,the experiments are comprehensively conducted to verify the security and effectiveness of our proposed framework and mechanisms.

industrial internet of thingsWLANsoftware-defined perimeterzero trustsecure access

商威、杨勇、张政洁、唐鼎

展开 >

国能河北定州发电有限责任公司 定州 073000

中国科学院信息工程研究所 第五实验室 北京 100085

工业物联网 无线局域网 软件定义边界 零信任 安全访问

国家能源集团河北电力公司科技项目

10094631 EB220024

2024

网络新媒体技术
中国科学院声学研究所

网络新媒体技术

CSTPCD
影响因子:0.208
ISSN:2095-347X
年,卷(期):2024.13(1)
  • 3