基于零信任架構(gòu)的線上培訓(xùn)安全平臺研究
網(wǎng)絡(luò)安全與數(shù)據(jù)治理
秦文遠(yuǎn),安寧
國務(wù)院國有資產(chǎn)監(jiān)督管理委員會干部教育培訓(xùn)中心
摘要: 新時(shí)代數(shù)智化技術(shù)的快速發(fā)展,使線上培訓(xùn)成為企業(yè)宣傳企業(yè)精神、學(xué)習(xí)新技術(shù)的重要抓手。在線上教育培訓(xùn)應(yīng)用廣泛的背景下,以保障平臺全流程支持培訓(xùn)業(yè)務(wù)開展為研究主線,依托現(xiàn)有零信任架構(gòu)的理念,構(gòu)建以可信終端環(huán)境感知、可信網(wǎng)絡(luò)環(huán)境感知、可信代理、動態(tài)訪問控制、信任評估、數(shù)據(jù)庫細(xì)粒度訪問控制六位一體的安全平臺。通過實(shí)時(shí)感知環(huán)境狀態(tài),動態(tài)賦予用戶最低權(quán)限,持續(xù)監(jiān)督用戶行為,讓平臺運(yùn)行時(shí)達(dá)到持續(xù)驗(yàn)證、動態(tài)授權(quán)、全局防御的目標(biāo)。平臺在信任評估模塊中引入自注意力機(jī)制,提高信任評估效率,保障培訓(xùn)平臺安全運(yùn)行,為培訓(xùn)組織單位構(gòu)建信息安全堡壘。
中圖分類號:TP309文獻(xiàn)標(biāo)識碼:ADOI:10.19358/j.issn.2097-1788.2025.05.002
引用格式:秦文遠(yuǎn),安寧. 基于零信任架構(gòu)的線上培訓(xùn)安全平臺研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2025,44(5):10-16.
引用格式:秦文遠(yuǎn),安寧. 基于零信任架構(gòu)的線上培訓(xùn)安全平臺研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2025,44(5):10-16.
Research on online training security system based on zero-trust architecture
Qin Wenyuan,An Ning
SASAC Education and Training System
Abstract: The rapid development of digital intelligence technology in the new era has made online training an important tool for enterprises to publicize their corporate spirit and learn new technologies. In this paper, against the background of the extensive application of online education and training, with the main research line of guaranteeing the platform′s full-process support for training business, relying on the concept of the existing zero-trust architecture, we construct a six-pronged security platform with trusted terminal environment awareness, trusted network environment awareness, trusted agent, dynamic access control, trust assessment, and fine-grained access control of the database. The platform senses the environment state in real time, dynamically grants users the lowest privilege, continuously monitors user behavior, and enables it to achieve the goals of continuous verification, dynamic authorization, and global defense during operation. The platform introduces the self-attention mechanism in the trust assessment module to improve the efficiency of trust assessment, ensure the safe operation of the training platform, and build an information security fortress for the training organizations.
Key words : online education and training;zero-trust security architecture; trust assessment; database security policy
引言
隨著信息化技術(shù)的發(fā)展,線上培訓(xùn)方式以不限場地、溝通迅捷的優(yōu)勢被廣泛應(yīng)用,逐漸成為常態(tài)化培訓(xùn)模式。但線上培訓(xùn)涉及用戶認(rèn)證、數(shù)據(jù)傳輸、權(quán)限管理、內(nèi)容保護(hù)等復(fù)雜業(yè)務(wù)邏輯,面臨的網(wǎng)絡(luò)威脅也逐漸增多。例如,遠(yuǎn)程用戶、多終端接入導(dǎo)致傳統(tǒng)網(wǎng)絡(luò)邊界模糊化,敏感課程內(nèi)容、用戶隱私數(shù)據(jù)易被竊取或?yàn)E用等安全問題時(shí)有發(fā)生,傳統(tǒng)安全模型逐漸在線上培訓(xùn)領(lǐng)域暴露出局限性。
零信任架構(gòu)對任何用戶、網(wǎng)絡(luò)均不信任,所有用戶均需通過身份驗(yàn)證后才可獲得最低權(quán)限,且平臺動態(tài)監(jiān)督用戶行為,保障從終端到數(shù)據(jù)庫的安全性。零信任架構(gòu)的安全理念逐漸被用戶認(rèn)可,成為線上培訓(xùn)平臺未來構(gòu)筑安全防線的重要抓手,為線上培訓(xùn)提供更靈活的細(xì)粒度安全防護(hù)手段。
本文詳細(xì)內(nèi)容請下載:
http://wldgj.com/resource/share/2000006541
作者信息:
秦文遠(yuǎn),安寧
(國務(wù)院國有資產(chǎn)監(jiān)督管理委員會干部教育培訓(xùn)中心,北京100053)
此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。