《電子技術應用》
您所在的位置:首頁 > 其他 > 設計應用 > 基于零信任架構的線上培訓安全平臺研究
基于零信任架構的線上培訓安全平臺研究
網絡安全與數(shù)據(jù)治理
秦文遠,安寧
國務院國有資產監(jiān)督管理委員會干部教育培訓中心
摘要: 新時代數(shù)智化技術的快速發(fā)展,使線上培訓成為企業(yè)宣傳企業(yè)精神、學習新技術的重要抓手。在線上教育培訓應用廣泛的背景下,以保障平臺全流程支持培訓業(yè)務開展為研究主線,依托現(xiàn)有零信任架構的理念,構建以可信終端環(huán)境感知、可信網絡環(huán)境感知、可信代理、動態(tài)訪問控制、信任評估、數(shù)據(jù)庫細粒度訪問控制六位一體的安全平臺。通過實時感知環(huán)境狀態(tài),動態(tài)賦予用戶最低權限,持續(xù)監(jiān)督用戶行為,讓平臺運行時達到持續(xù)驗證、動態(tài)授權、全局防御的目標。平臺在信任評估模塊中引入自注意力機制,提高信任評估效率,保障培訓平臺安全運行,為培訓組織單位構建信息安全堡壘。
中圖分類號:TP309文獻標識碼:ADOI:10.19358/j.issn.2097-1788.2025.05.002
引用格式:秦文遠,安寧. 基于零信任架構的線上培訓安全平臺研究[J].網絡安全與數(shù)據(jù)治理,2025,44(5):10-16.
Research on online training security system based on zero-trust architecture
Qin Wenyuan,An Ning
SASAC Education and Training System
Abstract: The rapid development of digital intelligence technology in the new era has made online training an important tool for enterprises to publicize their corporate spirit and learn new technologies. In this paper, against the background of the extensive application of online education and training, with the main research line of guaranteeing the platform′s full-process support for training business, relying on the concept of the existing zero-trust architecture, we construct a six-pronged security platform with trusted terminal environment awareness, trusted network environment awareness, trusted agent, dynamic access control, trust assessment, and fine-grained access control of the database. The platform senses the environment state in real time, dynamically grants users the lowest privilege, continuously monitors user behavior, and enables it to achieve the goals of continuous verification, dynamic authorization, and global defense during operation. The platform introduces the self-attention mechanism in the trust assessment module to improve the efficiency of trust assessment, ensure the safe operation of the training platform, and build an information security fortress for the training organizations.
Key words : online education and training;zero-trust security architecture; trust assessment; database security policy

引言

隨著信息化技術的發(fā)展,線上培訓方式以不限場地、溝通迅捷的優(yōu)勢被廣泛應用,逐漸成為常態(tài)化培訓模式。但線上培訓涉及用戶認證、數(shù)據(jù)傳輸、權限管理、內容保護等復雜業(yè)務邏輯,面臨的網絡威脅也逐漸增多。例如,遠程用戶、多終端接入導致傳統(tǒng)網絡邊界模糊化,敏感課程內容、用戶隱私數(shù)據(jù)易被竊取或濫用等安全問題時有發(fā)生,傳統(tǒng)安全模型逐漸在線上培訓領域暴露出局限性。

零信任架構對任何用戶、網絡均不信任,所有用戶均需通過身份驗證后才可獲得最低權限,且平臺動態(tài)監(jiān)督用戶行為,保障從終端到數(shù)據(jù)庫的安全性。零信任架構的安全理念逐漸被用戶認可,成為線上培訓平臺未來構筑安全防線的重要抓手,為線上培訓提供更靈活的細粒度安全防護手段。


本文詳細內容請下載:

http://ihrv.cn/resource/share/2000006541


作者信息:

秦文遠,安寧

(國務院國有資產監(jiān)督管理委員會干部教育培訓中心,北京100053)


Magazine.Subscription.jpg

此內容為AET網站原創(chuàng),未經授權禁止轉載。