• 查询稿件
  • 获取最新论文
  • 知晓行业信息

基于SDP的LTE-R网络零信任架构设计

Zero-trust architecture for LTE-R network based on SDP

  • 摘要: 随着LTE-R(Long Term Evolution for Railways)网络的发展,传统安全架构难以应对日益复杂的安全威胁,特别是针对网络边界逐渐模糊、“非法用户”越权访问等问题。文章结合“永不信任,始终验证”的零信任理念,提出一种基于软件定义边界(SDP,Software Defined Perimeter)的LTE-R网络零信任架构。该架构融合单包授权(SPA,Single Packet Authorization)、持续认证机制和行为审计策略,实现服务端口隐身、最小权限控制及动态权限管理,有效防御横向渗透、中间人攻击和端口扫描,为保障LTE-R核心调度系统安全和铁路通信网络的零信任转型提供了可行路径。

     

    Abstract: With the development of LTE-R (Long Term Evolution for Railways) networks, traditional security architectures struggle to address increasingly complex security threats, particularly issues such as the blurring network boundaries and unauthorized access by "illegal users". This paper proposed a zero-trust architecture for LTE-R based on Software Defined Perimeter (SDP), by combining the zero-trust principle of "never trust, always verify". This architecture combined Single Packet Authorization (SPA), continuous authentication mechanisms, and behavioral audit strategies to implement service port invisibility, minimal privilege control, and dynamic permission management. It effectively defends against lateral infiltration, man-in-the-middle attacks, and port scanning, providing a feasible pathway to safeguard LTE-R core dispatching systems and facilitate the zero-trust transformation of railway communication networks.

     

/

返回文章
返回