首页|基于零信任体系的数字身份安全平台设计与研究

基于零信任体系的数字身份安全平台设计与研究

扫码查看
高校在统一身份认证和访问控制方面的防控仍较薄弱,面对层出不穷的网络安全威胁显得力不从心.为此,提出基于零信任体系的数字身份安全平台解决方案.引入零信任SDP技术搭建高校零信任安全架构,重构统一身份认证与访问授权平台,按功能划分DMZ微隔离区,实现用户身份统一管理、平台多因素多维认证、服务端口和设备信息对外动态隐藏、访问链接动态授权.结合四网融合场景分析校内外5G用户、校内Wi-Fi用户、校园网用户和校外互联网用户访问数字身份安全平台的准入方式.研究成果极大地丰富了智慧校园研究内容,也为高校重构和升级统一身份认证和访问授权平台提供一种全新的解决思路.
Design and Research of Digital Identity Security Platform Based on Zero Trust System
Universities are still weak in unified identity authentication and access control,which makes them unable to cope with network security threats.Therefore,this paper proposes a digital identity security platform solution based on zero trust sys-tem.The zero trust SDP technology is introduced to build zero-trust security architecture in universities,and a unified identity authentication and access authorization platform is reconstructed.The DMZ micro-isolation zone is divided according to func-tions to achieve unified user identity management,multi-factor and multi-dimensional authentication of the platform,dynamic hiding of service ports and device information,and dynamic authorization of access links.The access mode of 5G users,Wi-Fi users,campus network users and Internet users outside the campus to access the digital identity security platform is analyzed in combination with the four networks convergence scenario.The research results greatly enrich the content of smart campus re-search,and also provide a new solution for universities to reconstruct and upgrade the unified identity authentication and access authorization platform.

zero trust systemdigital identityunified authenticationaccess controlnetwork security

吕忠亭、朱丹妮、雷世斌、张婕

展开 >

延安职业技术学院网络信息中心,陕西,延安 716000

延安职业技术学院公共课教学部,陕西,延安 716000

延安职业技术学院士官学院,陕西,延安 716000

零信任体系 数字身份 统一认证 访问控制 网络安全

陕西省职业技术教育学会教育教学改革研究项目

2022SZX117

2024

微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
年,卷(期):2024.40(2)
  • 12