微型电脑应用2024,Vol.40Issue(7) :249-252.

基于零信任的"一机多网"云桌面设计

Design of"One Machine,Multiple Networks"Cloud Desktop Based on Zero Trust

胡钧超 黄海江 张悦
微型电脑应用2024,Vol.40Issue(7) :249-252.

基于零信任的"一机多网"云桌面设计

Design of"One Machine,Multiple Networks"Cloud Desktop Based on Zero Trust

胡钧超 1黄海江 1张悦2
扫码查看

作者信息

  • 1. 中国信息通信研究院,信息管理中心,北京 100191
  • 2. 北京农村商业银行股份有限公司,软件开发中心,北京 100029
  • 折叠

摘要

企事业单位内通常使用传统PC作为办公桌面终端,安全性难以保证,容易发生文件泄露、网络攻击等安全事件,同时,系统间被要求网络隔离,导致办公桌需要放置多台PC,严重占用办公桌空间,浪费成本.针对上述问题,以云桌面作为桌面终端,融合零信任的安全理念,提出一种基于零信任的"一机多网"云桌面架构,此架构在传统云桌面的基础上,使用网络隔离切换器保证网络的传输安全以及强逻辑隔离,并将公网访问端口匿名化,进一步提升桌面终端安全性,同时有效减少传统办公PC的冗余.

Abstract

In enterprises and institutions,traditional PCs are commonly used as office desktop terminals,but their security can-not be guaranteed,which makes them susceptible to security incidents such as file leaks and network attacks.Moreover,net-work isolation is required between systems necessitates the placement of multiple PCs on office desks,resulting in significant space occupation and cost wastage.To address these issues,this paper takes cloud desktop as terminal and integrates the secu-ring concept of zero trust,proposes a"one machine,multiple networks"cloud desktop architecture based on the zero-trust se-curity concept.Building upon traditional cloud desktops,this architecture employs a network isolation switch to ensure secure network transmission and strong logical isolation.Additionally,it anonymizes the public network access port to enhance the se-curity of desktop terminals while reducing the redundancy of traditional office PCs.

关键词

办公终端/零信任模型/云桌面架构/网络安全

Key words

office terminal/zero-trust model/cloud desktop architecture/network security

引用本文复制引用

出版年

2024
微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
段落导航相关论文