• • 上一篇    下一篇

一种单向安全隔离与信息交换机制

陈达%马威%李晓勇   

  • 基金资助:
    教育部创新?哦臃⒄辜苹甗IRT201206]、高等学校博士学科点专项科研基金(20120009110007)

One-way Communication Mechanism for Network Security Isolation and Information Exchange

CHEN Da%MA Wei%LI Xiao-yong   

  • About author:北京交通大学计算机与信息技术学院,北京,100044

摘要: 随着互联网的高速发展,敏感信息泄漏事件频繁发生,不同安全级网络之间安全隔离与信息交换问题已经成为国内外信息安全方面的研究热点。通过分析现有隔离技术的优势与不足,文章提出一种单向安全隔离与交换机制,克服了单向物理隔离条件下信息交换不可靠问题,并且对潜在的隐蔽通道进行严格控制,协调了不同安全级网络之间隔离与信息交换之间的矛盾。该机制具备物理级安全隔离,信息可靠传输,易于扩展等优点,可应用于多级安全网络隔离与信息交换场合。

Abstract: With the rapid development of the Internet, information leakage occurred frequently. Today, network security isolation and information exchange technology has become a research focus in information security. Analyzing the advantages and disadvantages of the existing isolation techniques, this paper proposed a mechanism for security isolation and information exchange, which overcomes unreliability issue in one-way communication with the potential covert channels under controlled. It coordinates the contradiction between security isolation and information exchange among different security level networks. In addition, the mechanism also has advantages, such as security isolation in physical level, reliable communication and good expansibility. It is well suited for multi-level security isolation and information exchange occasions.