|国家科技期刊平台
首页|期刊导航|信息安全研究|零信任模型下的智能权限管理系统研究与实践

零信任模型下的智能权限管理系统研究与实践OA北大核心CSTPCD

Research and Implementation of Intelligent Permission Management System Under Zero Trust Model

中文摘要英文摘要

零信任模型给各种场景下的实际业务提出新的需求和挑战.过去的权限管理实践中,往往是由管理员人工赋予用户权限.然而,这种方式存在着许多问题,特别是在面对人员调动、权限更改和信息陈旧等情况时,系统无法及时自动调整权限,可能导致安全问题,甚至给黑客提供了攻击的突破口,造成严重的安全隐患.为了解决这些问题,必须在实际应用中紧密结合业务需求,实现权限的智能理解、调整和分配.旨在探讨在零信任模型下构建智能权限管理系统的研究与实践,为企业提供更加安全、高效的权限管理解决方案.

The zero trust model puts forward new requirements and challenges for actual businesses in various scenarios.In the past,in the practice of permission management,administrators often manually granted users permissions.However,there are many problems with this method,especially in the face of personnel transfer,permission change,and outdated information,the system cannot automatically adjust the permission in time,which may lead to security problems,and even provide hackers with a breakthrough in attack,causing serious security risks.In order to solve these problems,it is necessary to closely integrate business needs in practical applications to realize the intelligent understanding,adjustment,and allocation of permissions.The purpose of this paper is to discuss the research and practice of building an intelligent permission management system under the zero trust model,so as to provide enterprises with a more secure and efficient permission management solution.

张逸飞;李梦婕

中国科学院信息工程研究所 北京 100085

计算机与自动化

零信任架构权限管理网络安全按需授权数据安全

zero trust architectureauthority managementnetwork securityon-demand licensingdata security

《信息安全研究》 2024 (010)

912-920 / 9

10.12379/j.issn.2096-1057.2024.10.04

评论