浏览全部资源
扫码关注微信
[ "何国锋(1976-),男,博士,中国电信股份有限公司研究院应用安全研究所所长、教授级高级工程师,主要研究方向为移动应用安全、Web 应用安全、代码安全、PKI体系等" ]
网络出版日期:2020-12,
纸质出版日期:2020-12-20
移动端阅览
何国锋. 零信任架构在5G云网中应用防护的研究[J]. 电信科学, 2020,36(12):123-132.
Guofeng HE. Application protection in 5G cloud network using zero trust architecture[J]. Telecommunications science, 2020, 36(12): 123-132.
何国锋. 零信任架构在5G云网中应用防护的研究[J]. 电信科学, 2020,36(12):123-132. DOI: 10.11959/j.issn.1000-0801.2020325.
Guofeng HE. Application protection in 5G cloud network using zero trust architecture[J]. Telecommunications science, 2020, 36(12): 123-132. DOI: 10.11959/j.issn.1000-0801.2020325.
通过对5G云网融合时代的安全需求分析,研究零信任的基本原则,包括不依赖位置、不信任流量、动态访问控制等;研究零信任的基本架构,结合5G云网架构,提出了3种可行的应用防护方案,包括客户自建的OTT模式、利用现有VPDN改造模式、公共零信任架构模式,并进行了比较。分析了客户在5G云网中的应用场景,包括远程访问、安全上云、移动办公等,以及在这些场景中零信任架构可以给客户带来的价值,如实现应用隐藏、动态控制,确保应用的安全性。
Based on the analysis of security requirements in the era of 5G cloud-network convergence
the basic principles of zero trust were studied
including not rely on location
untrusted traffic
and dynamic access control.The basic architecture of zero-trust was studied
combining with 5G cloud network architecture
the feasible application protection solutions include the customer-built OTT model
the use of the existing VPDN model
and the public zero-trust architecture model was proposed and compared.The application scenarios of customers in 5G cloud network were analyzed
including remote access
secure cloud
mobile office
etc.In these scenarios
the value that zero-trust architecture can bring to customers was proposed
such as application hiding and dynamic control
ensure the application safety.
OSBORN B , MCWILLIAMS J , BEYER B , et al . BeyondCorp:design to deployment at Google [Z ] .2016. 2016 .
SCA . SDP specification 1.0 [S ] . 1994 .
网络安全架构:零信任架构正在标准化 [EB ] . 2019 .
Network security architecture:zero trust architecture is being standardized [EB ] . 2019 .
埃文·吉尔曼,道格·巴斯 , 零信任网络在不可信网络中构建安全系统 [M ] . 奇安信身份安全实验室,译.北京 : 人民邮电出版社 , 2019 .
GILMAN E , BARTH G . Zero trust networks [M ] . Translated by Qi-Anxin Technology Group Inc . Beijing : Posts & Telecom PressPress , 2019 .
吴伟 , 张文强 , 杨广铭 , 等 . 5G承载网的“SRv6+EVPN”技术研究与规模部署 [J ] . 电信科学 , 2020 , 36 ( 8 ): 43 - 52 .
WU W , ZHANG W Q , YANG G M , et al . SRv6 +EVPN technology research and scale deployment of 5G bearer network [J ] . Telecommunications Science , 2020 , 36 ( 8 ): 43 - 52 .
马培勇 , 吴伟 , 张文强 , 等 . 5G 承载网关键技术及发展 [J ] . 电信科学 , 2020 , 36 ( 9 ): 122 - 130 .
MA P Y , WU W , ZHANG W Q , et al . Key technologies and development of 5G bearer network [J ] . Telecommunications Science , 2020 , 36 ( 9 ): 122 - 130 .
何晓明 , 岳萍 , 卢泉 , 等 . 面向5G承载的IP RAN演进及关键技术 [J ] . 电信科学 , 2020 , 36 ( 3 ): 125 - 135 .
HE X M , YUE P , LU Q , et al . Evolution and key technologies of 5G-oriented IP RAN [J ] . Telecommunications Science , 2020 , 36 ( 3 ): 125 - 135 .
0
浏览量
1166
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构