首页|基于零信任的"一机多网"云桌面设计

基于零信任的"一机多网"云桌面设计

扫码查看
企事业单位内通常使用传统PC作为办公桌面终端,安全性难以保证,容易发生文件泄露、网络攻击等安全事件,同时,系统间被要求网络隔离,导致办公桌需要放置多台PC,严重占用办公桌空间,浪费成本.针对上述问题,以云桌面作为桌面终端,融合零信任的安全理念,提出一种基于零信任的"一机多网"云桌面架构,此架构在传统云桌面的基础上,使用网络隔离切换器保证网络的传输安全以及强逻辑隔离,并将公网访问端口匿名化,进一步提升桌面终端安全性,同时有效减少传统办公PC的冗余.
Design of"One Machine,Multiple Networks"Cloud Desktop Based on Zero Trust
In enterprises and institutions,traditional PCs are commonly used as office desktop terminals,but their security can-not be guaranteed,which makes them susceptible to security incidents such as file leaks and network attacks.Moreover,net-work isolation is required between systems necessitates the placement of multiple PCs on office desks,resulting in significant space occupation and cost wastage.To address these issues,this paper takes cloud desktop as terminal and integrates the secu-ring concept of zero trust,proposes a"one machine,multiple networks"cloud desktop architecture based on the zero-trust se-curity concept.Building upon traditional cloud desktops,this architecture employs a network isolation switch to ensure secure network transmission and strong logical isolation.Additionally,it anonymizes the public network access port to enhance the se-curity of desktop terminals while reducing the redundancy of traditional office PCs.

office terminalzero-trust modelcloud desktop architecturenetwork security

胡钧超、黄海江、张悦

展开 >

中国信息通信研究院,信息管理中心,北京 100191

北京农村商业银行股份有限公司,软件开发中心,北京 100029

办公终端 零信任模型 云桌面架构 网络安全

2024

微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
年,卷(期):2024.40(7)