信息安全研究 ›› 2021, Vol. 7 ›› Issue (7): 598-605.

• 学术论文 • 上一篇    下一篇

数字身份安全治理研究

李 俊    柴海新   

  1. (国民认证科技(北京)有限公司 北京 100085)
  • 出版日期:2021-07-09 发布日期:2021-07-08
  • 作者简介:李 俊 硕士,主要研究方向为身份认证、信息安全 lijun@gmrz-bj.com 柴海新 博士,主要研究方向为身份认证、信息安全 chaihx@gmrz-bj.com

Research on Secure Governance of Digital Identity 

  • Online:2021-07-09 Published:2021-07-08
  • Contact: 李俊

摘要: 万物互联时代,网络空间中实体身份规模迅猛扩大,面临的安全风险日益增加,对实施数字身份安全治理提出了挑战。首先对数字身份的基本概念进行阐述,明确了身份、凭证和鉴别器的含义,提出了数字身份的分类。然后描述了数字身份模型架构和数字身份生命周期,并给出了围绕数字身份的活动及其角色和功能。之后针对数字身份模型各活动所存在的安全风险提出了安全保障框架,并分别阐述了安全保障框架的三种不同保障等级:身份保障等级、鉴别器保障等级和联合保障等级。最后给出了实现数字身份安全治理的思路,包括制定战略、建立制度、运用技术、构建生态和加强监管。

关键词: 数字身份, 安全治理, 身份模型, 身份核验, 登记, 鉴别, 联合, 保障框架, 凭证, 鉴别器

Abstract: In the era of Internet of things, the scale of entity identities in cyberspace is expanding rapidly, and the security risks are increasing, which challenges the implementation of digital identity secure governance. Firstly, the basic concept of digital identity is described, the meaning of identity, credential and authenticator is defined, and the classification of digital identity is proposed. Then the architecture of digital identity model and the life cycle of digital identity are described, and the activities, roles and functions around digital identity are elaborated. Then, according to the security risks existing in the activities of the digital identity model, the security assurance framework is proposed, and three different security levels of assurance with the security framework are elaborated: identity assurance level, authenticator assurance level and federation assurance level. Finally, the ideas of digital identity secure governance are proposed, including making strategy, establishing rules and regulations, utilizing technologies, building the ecosystem and strengthening supervision.

Key words: digital identity, secure governance, identity model, identity proofing, enrolment, authentication, federation, assurance framework, credential, authenticator