• 查询稿件
  • 获取最新论文
  • 知晓行业信息
锁向荣, 齐胜, 张悦斌, 朱贺. 铁路云平台细粒度访问控制方案研究[J]. 铁路计算机应用, 2021, 30(4): 45-49.
引用本文: 锁向荣, 齐胜, 张悦斌, 朱贺. 铁路云平台细粒度访问控制方案研究[J]. 铁路计算机应用, 2021, 30(4): 45-49.
SUO Xiangrong, QI Sheng, ZHANG Yuebin, ZHU He. Research on fine-grained access control scheme of railway cloud platform[J]. Railway Computer Application, 2021, 30(4): 45-49.
Citation: SUO Xiangrong, QI Sheng, ZHANG Yuebin, ZHU He. Research on fine-grained access control scheme of railway cloud platform[J]. Railway Computer Application, 2021, 30(4): 45-49.

铁路云平台细粒度访问控制方案研究

Research on fine-grained access control scheme of railway cloud platform

  • 摘要: 为进一步提高铁路云平台网络安全防护能力,参照信息系统安全等级保护的有关要求,在铁路云平台网络安全保障体系框架下,提出一种铁路云平台细粒度访问控制方案;该方案采用零信任访问控制策略,由代理程序、数据总线、安全网关和安全模块4个部件协同完成安全的数据传输,利用标记技术实现域内和跨域的细粒度强制访问控制,在保持原有安全部署的基础上,有效提升铁路云平台的安全防护能力。

     

    Abstract: In order to further improve the ability of network security protection of railway cloud platform, a fine-grained access control scheme of railway cloud platform is put forward in the framework of network security protection syetem for railway cloud platform according to the basline of classified protection of information system security. By adopting zero trust access control policy, secure data trassimission is completed through the interaction of four major components including the agent, data bus, security gateway and security module. Besides, labeling technique is adopted to realize fine-grained mandatory access control in and across domains, effectively improving the security protection ability of the cloud platform while maintaining the existing deployment of security protection.

     

/

返回文章
返回