《计算机应用》唯一官方网站 ›› 2023, Vol. 43 ›› Issue (4): 1142-1150.DOI: 10.11772/j.issn.1001-9081.2022030453

• 网络空间安全 • 上一篇    

零信任网络及其关键技术综述

王群1, 袁泉2, 李馥娟1(), 夏玲玲1   

  1. 1.江苏警官学院 计算机信息与网络安全系,南京 210031
    2.中国药科大学 图书与信息中心,南京 210009
  • 收稿日期:2022-04-08 修回日期:2022-06-13 接受日期:2022-06-15 发布日期:2023-04-11 出版日期:2023-04-10
  • 通讯作者: 李馥娟
  • 作者简介:王群(1971—),男,甘肃天水人,教授,博士,CCF会员,主要研究方向:网络空间安全、网络体系结构与协议;
    袁泉(1981—),男,江苏东台人,高级工程师,博士研究生,主要研究方向:网络安全与管理;
    夏玲玲(1988—),女,江苏盐城人,副教授,博士,主要研究方向:网络空间安全、复杂网络传播动力学。
  • 基金资助:
    国家自然科学基金资助项目(61802155);江苏省高校自然科学研究重大项目(20KJA520004);江苏省高校优秀科技创新团队;公安技术、网络空间安全“十四五”江苏省重点学科;江苏省社会科学基金资助项目(21MLD012)

Review of zero trust network and its key technologies

Qun WANG1, Quan YUAN2, Fujuan LI1(), Lingling XIA1   

  1. 1.Department of Computer Information and Cybersecurity,Jiangsu Police Institute,Nanjing Jiangsu 210031,China
    2.Library and Information Center,China Pharmaceutical University,Nanjing Jiangsu 210009,China
  • Received:2022-04-08 Revised:2022-06-13 Accepted:2022-06-15 Online:2023-04-11 Published:2023-04-10
  • Contact: Fujuan LI
  • About author:WANG Qun, born in 1971, Ph. D., professor. His research interests include cyberspace security, network architecture and protocol.
    YUAN Quan, born in 1981, Ph. D. candidate, senior engineer. His research interests include network security and management.
    XIA Lingling, born in 1988, Ph. D., associate professor. Her research interests include cyberspace security, spreading dynamics of complex network.
  • Supported by:
    National Natural Science Foundation of China(61802155);Natural Science Research Major Project of Jiangsu Provincial Colleges and Universities(20KJA520004);Excellent Scientific and Technological Innovation team of Universities in Jiangsu, Jiangsu Province Key Disciplines of Public Security Technology and Cyberspace Security during the “14th Five Year Plan”, Jiangsu Provincial Social Science Fund Project(21MLD012)

摘要:

在网络安全威胁日趋严峻、安全防御手段日益复杂的情况下,零信任网络能够对传统边界安全架构进行全新的评估和审视。零信任强调不要永远信任,而且要持续验证,而零信任网络不以位置标识身份,所有访问控制严格执行最小权限,所有访问过程被实时跟踪和动态评估。首先,给出了零信任网络的基本定义,指出了传统边界安全暴露出的主要问题,并描述了零信任网络模型;其次,分析了软件定义边界(SDP)、身份和访问管理、微隔离、自动配置管理系统(ACMS)等零信任网络中的关键技术;最后,对零信任网络进行了总结,并展望未来发展。

关键词: 零信任, 网络安全, 安全模型, 自动化系统, 微隔离

Abstract:

With increasingly severe network security threats and increasingly complex security defense means, zero trust network is a new evaluation and review of traditional boundary security architecture. Zero trust emphasizes never always trusting anything and verifying things continuously. Zero trust network emphasizes that the identity is not identified by location, all access controls strictly execute minimum permissions, and all access processes are tracked in real time and evaluated dynamically. Firstly, the basic definition of zero trust network was given, the main problems of traditional perimeter security were pointed out, and the zero trust network model was described. Secondly, the key technologies of zero trust network, such as Software Defined Perimeter (SDP), identity and access management, micro segmentation and Automated Configuration Management System (ACMS), were analyzed. Finally, zero trust network was summarized and its future development was prospected.

Key words: zero trust, network security, security model, automatic system, micro segmentation

中图分类号: