信息网络安全 ›› 2014, Vol. 14 ›› Issue (9): 105-108.doi: 10.3969/j.issn.1671-1122.2014.09.024

• 入选论文 • 上一篇    下一篇

物理隔离脆弱性分析及对策

石军   

  1. 北京市保密技术检查中心,北京 100005
  • 收稿日期:2014-08-06 出版日期:2014-09-01
  • 作者简介:石军(1975-),男,山东,高级工程师,硕士,主要研究方向:混沌在通信系统及信息技术中的应用、通信信号识别及信息安全等。

Analysis of Physics Isolation Vulnerability and Its Countermeasure

SHI Jun   

  1. Institute of Information Security Technology, Beijing State Secrets Bureau, Beijing 100005, China
  • Received:2014-08-06 Online:2014-09-01

摘要: 针对“网震”和“斯诺登”事件物理隔离存在边界安全被突破的事实,其能否起到真正安全隔离作用成为重点关注的问题。文章介绍了物理隔离的三个实现技术及其2个演化进程并对每一个进程做个安全性分析,指出了目前物理隔离存在的安全问题,给出了建立新型物理隔离边界安全防护的建议是建立全局文件交换管理体系、统一文件交换格式、建立物理电磁泄漏发射防护要求、防内存泄漏等,进而提出基于单向导入技术和量子密码技术物理隔离新的组网方式并分析了适用场景,提出了安全隔离和信息交换系统应解决的一系列问题,指出新兴密码技术对物理隔离是一个终结挑战。希望文章的研究结果能对网络边界安全防护工作的进一步开展起到积极的重大推动作用。

关键词: 物理隔离, 电磁泄漏发射防护, 网震, 边界安全, 量子保密通信

Abstract: In view of the “Stuxnet” and “Snowden” events, physical isolation exists the fact that network security perimeter has been broken,and its real security isolation effect arouse bitter controversy. This paper introduces three implementation technology approaches and two evolution processes of physical isolation and make safety analysis of each process. Some proposals related to physical isolation security problems are discussed; for instance, to establish global file exchange management system, to unify file exchange format, to establish electromagnetic compromising emanation protection requirements and to prevent memory information leakage. The network connection new methods based on one-way input technology and quantum cryptography are proposed, and its applicable occasions are analyzed. Problems to be solved on security segregation and information-exchanging product are proposed and emerging cryptology technology will be the end of physical isolation. It hope that the research results to the further development of network security perimeter protection work play a positive role.

Key words: physics isolation, electromagnetic compromising emanation, stuxnet, network security perimeter, quantum private communication