基于零信任架構的線上培訓安全平臺研究
網絡安全與數據治理
秦文遠,安寧
國務院國有資產監督管理委員會干部教育培訓中心
摘要: 新時代數智化技術的快速發展,使線上培訓成為企業宣傳企業精神、學習新技術的重要抓手。在線上教育培訓應用廣泛的背景下,以保障平臺全流程支持培訓業務開展為研究主線,依托現有零信任架構的理念,構建以可信終端環境感知、可信網絡環境感知、可信代理、動態訪問控制、信任評估、數據庫細粒度訪問控制六位一體的安全平臺。通過實時感知環境狀態,動態賦予用戶最低權限,持續監督用戶行為,讓平臺運行時達到持續驗證、動態授權、全局防御的目標。平臺在信任評估模塊中引入自注意力機制,提高信任評估效率,保障培訓平臺安全運行,為培訓組織單位構建信息安全堡壘。
中圖分類號:TP309文獻標識碼:ADOI:10.19358/j.issn.2097-1788.2025.05.002
引用格式:秦文遠,安寧. 基于零信任架構的線上培訓安全平臺研究[J].網絡安全與數據治理,2025,44(5):10-16.
引用格式:秦文遠,安寧. 基于零信任架構的線上培訓安全平臺研究[J].網絡安全與數據治理,2025,44(5):10-16.
Research on online training security system based on zero-trust architecture
Qin Wenyuan,An Ning
SASAC Education and Training System
Abstract: The rapid development of digital intelligence technology in the new era has made online training an important tool for enterprises to publicize their corporate spirit and learn new technologies. In this paper, against the background of the extensive application of online education and training, with the main research line of guaranteeing the platform′s full-process support for training business, relying on the concept of the existing zero-trust architecture, we construct a six-pronged security platform with trusted terminal environment awareness, trusted network environment awareness, trusted agent, dynamic access control, trust assessment, and fine-grained access control of the database. The platform senses the environment state in real time, dynamically grants users the lowest privilege, continuously monitors user behavior, and enables it to achieve the goals of continuous verification, dynamic authorization, and global defense during operation. The platform introduces the self-attention mechanism in the trust assessment module to improve the efficiency of trust assessment, ensure the safe operation of the training platform, and build an information security fortress for the training organizations.
Key words : online education and training;zero-trust security architecture; trust assessment; database security policy
引言
隨著信息化技術的發展,線上培訓方式以不限場地、溝通迅捷的優勢被廣泛應用,逐漸成為常態化培訓模式。但線上培訓涉及用戶認證、數據傳輸、權限管理、內容保護等復雜業務邏輯,面臨的網絡威脅也逐漸增多。例如,遠程用戶、多終端接入導致傳統網絡邊界模糊化,敏感課程內容、用戶隱私數據易被竊取或濫用等安全問題時有發生,傳統安全模型逐漸在線上培訓領域暴露出局限性。
零信任架構對任何用戶、網絡均不信任,所有用戶均需通過身份驗證后才可獲得最低權限,且平臺動態監督用戶行為,保障從終端到數據庫的安全性。零信任架構的安全理念逐漸被用戶認可,成為線上培訓平臺未來構筑安全防線的重要抓手,為線上培訓提供更靈活的細粒度安全防護手段。
本文詳細內容請下載:
http://m.jysgc.com/resource/share/2000006541
作者信息:
秦文遠,安寧
(國務院國有資產監督管理委員會干部教育培訓中心,北京100053)
此內容為AET網站原創,未經授權禁止轉載。