《電子技術(shù)應(yīng)用》
您所在的位置:首頁 > 其他 > 设计应用 > 基于零信任架构的线上培训安全平台研究
基于零信任架构的线上培训安全平台研究
网络安全与数据治理
秦文远,安宁
国务院国有资产监督管理委员会干部教育培训中心
摘要: 新时代数智化技术的快速发展,使线上培训成为企业宣传企业精神、学习新技术的重要抓手。在线上教育培训应用广泛的背景下,以保障平台全流程支持培训业务开展为研究主线,依托现有零信任架构的理念,构建以可信终端环境感知、可信网络环境感知、可信代理、动态访问控制、信任评估、数据库细粒度访问控制六位一体的安全平台。通过实时感知环境状态,动态赋予用户最低权限,持续监督用户行为,让平台运行时达到持续验证、动态授权、全局防御的目标。平台在信任评估模块中引入自注意力机制,提高信任评估效率,保障培训平台安全运行,为培训组织单位构建信息安全堡垒。
中圖分類號(hào):TP309文獻(xiàn)標(biāo)識(shí)碼:ADOI:10.19358/j.issn.2097-1788.2025.05.002
引用格式:秦文遠(yuǎn),安寧. 基于零信任架構(gòu)的線上培訓(xùn)安全平臺(tái)研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2025,44(5):10-16.
Research on online training security system based on zero-trust architecture
Qin Wenyuan,An Ning
SASAC Education and Training System
Abstract: The rapid development of digital intelligence technology in the new era has made online training an important tool for enterprises to publicize their corporate spirit and learn new technologies. In this paper, against the background of the extensive application of online education and training, with the main research line of guaranteeing the platform′s full-process support for training business, relying on the concept of the existing zero-trust architecture, we construct a six-pronged security platform with trusted terminal environment awareness, trusted network environment awareness, trusted agent, dynamic access control, trust assessment, and fine-grained access control of the database. The platform senses the environment state in real time, dynamically grants users the lowest privilege, continuously monitors user behavior, and enables it to achieve the goals of continuous verification, dynamic authorization, and global defense during operation. The platform introduces the self-attention mechanism in the trust assessment module to improve the efficiency of trust assessment, ensure the safe operation of the training platform, and build an information security fortress for the training organizations.
Key words : online education and training;zero-trust security architecture; trust assessment; database security policy

引言

隨著信息化技術(shù)的發(fā)展,線上培訓(xùn)方式以不限場地、溝通迅捷的優(yōu)勢被廣泛應(yīng)用,逐漸成為常態(tài)化培訓(xùn)模式。但線上培訓(xùn)涉及用戶認(rèn)證、數(shù)據(jù)傳輸、權(quán)限管理、內(nèi)容保護(hù)等復(fù)雜業(yè)務(wù)邏輯,面臨的網(wǎng)絡(luò)威脅也逐漸增多。例如,遠(yuǎn)程用戶、多終端接入導(dǎo)致傳統(tǒng)網(wǎng)絡(luò)邊界模糊化,敏感課程內(nèi)容、用戶隱私數(shù)據(jù)易被竊取或?yàn)E用等安全問題時(shí)有發(fā)生,傳統(tǒng)安全模型逐漸在線上培訓(xùn)領(lǐng)域暴露出局限性。

零信任架構(gòu)對(duì)任何用戶、網(wǎng)絡(luò)均不信任,所有用戶均需通過身份驗(yàn)證后才可獲得最低權(quán)限,且平臺(tái)動(dòng)態(tài)監(jiān)督用戶行為,保障從終端到數(shù)據(jù)庫的安全性。零信任架構(gòu)的安全理念逐漸被用戶認(rèn)可,成為線上培訓(xùn)平臺(tái)未來構(gòu)筑安全防線的重要抓手,為線上培訓(xùn)提供更靈活的細(xì)粒度安全防護(hù)手段。


本文詳細(xì)內(nèi)容請(qǐng)下載:

http://m.ihrv.cn/resource/share/2000006541


作者信息:

秦文遠(yuǎn),安寧

(國務(wù)院國有資產(chǎn)監(jiān)督管理委員會(huì)干部教育培訓(xùn)中心,北京100053)


Magazine.Subscription.jpg

此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。

相關(guān)內(nèi)容