信息网络安全 ›› 2020, Vol. 20 ›› Issue (9): 62-66.doi: 10.3969/j.issn.1671-1122.2020.09.013

• 入选论文 • 上一篇    下一篇

云安全体系结构设计研究

余小军1(), 吴亚飚1, 张玉清2   

  1. 1. 北京天融信科技有限公司,北京 100085
    2. 中国科学院大学,北京 100049
  • 收稿日期:2020-07-16 出版日期:2020-09-10 发布日期:2020-10-15
  • 通讯作者: 余小军 E-mail:yu_xiaojun@topsec.com.cn
  • 作者简介:余小军(1980—),男,浙江,高级工程师,博士,主要研究方向为云计算安全、数据安全|吴亚飚(1971—),男,福建,高级工程师,硕士,主要研究方向为网络安全|张玉清(1966—),男,陕西,教授,博士,主要研究方向为网络与信息系统安全

Research on the Design of Cloud Security Architecture

YU Xiaojun1(), WU Yabiao1, ZHANG Yuqing2   

  1. 1. Beijing Topsec Science & Technology Inc., Beijing 100085, China
    2. University of Chinese Academy of Sciences, Beijing 100049, China
  • Received:2020-07-16 Online:2020-09-10 Published:2020-10-15
  • Contact: Xiaojun YU E-mail:yu_xiaojun@topsec.com.cn

摘要:

不断演进的云环境给安全体系结构设计带来了挑战,文章首先回顾了现有体系结构研究成果,从设计动机、主要思想、典型方案及评价4个角度进行了详细说明。然后借鉴多种先进技术思想,设计了一个具有可定义、可重构、可演进的云安全体系结构,分析表明了该体系结构的合理性和先进性。最后对云安全体系结构的进一步研究提出了建议。

关键词: 云安全体系结构, 责任共担, 面向服务化, 云可信, 软件定义

Abstract:

The evolving cloud environment has brought great challenges to the design of security architecture. This paper analyzes the existing work in detail from four aspects of design motivation, typical scheme, main ideas and evaluation, clarifies the common characteristics of the existing work. Then, a definable, reconfigurable and evolvable cloud security architecture is designed based on many advanced technology ideas, and the analysis shows the rationality and advanced nature of the new architecture. At last, it points out the further research directions of the current security architecture research work.

Key words: cloud security architecture, shared responsibility, service-oriented, cloud trust, software-defined

中图分类号: