信息安全研究 ›› 2022, Vol. 8 ›› Issue (6): 554-.

• 工业控制网络安全专题 • 上一篇    下一篇

工业互联网密码应用研究

董贵山1张文科2罗影2唐林2刘波1冷昌琦2李恺1许莹莹2   

  1. 1(中国电子科技网络信息安全有限公司成都610041)
    2(工业信息安全(四川)创新中心有限公司技术研究部成都610041)
  • 出版日期:2022-06-05 发布日期:2022-06-03
  • 通讯作者: 董贵山 博士,研究员.主要研究方向为工业信息安全. mountain_dong@163.com
  • 作者简介:董贵山 博士,研究员.主要研究方向为工业信息安全. mountain_dong@163.com 张文科 硕士,研究员.主要研究方向为工业控制系统安全、密码技术应用. zhangwenke@icics.com.cn 罗影 硕士,高级工程师.主要研究方向为密码技术应用、工业控制系统安全. luoying@icics.com.cn 唐林 硕士,研究员.主要研究方向为工业控制系统安全. tanglin@icics.com.cn 刘波 硕士,高级工程师.主要研究方向为工业互联网安全. liubo@cetc30.com.cn 冷昌琦 硕士,工程师.主要研究方向为工业软件安全. lengchangqi@icics.com.cn 李恺 硕士,工程师.主要研究方向为工业互联网安全. likai@cetc30.com.cn 许莹莹 硕士,工程师.主要研究方向为工业信息系统安全. xuyingying@icics.com.cn

  • Online:2022-06-05 Published:2022-06-03

摘要: 工业互联网以网络为基础、以平台为核心、以安全为保障,通过大规模关键网络基础设施连接所有行业要素和整个产业链,实时采集、分析行业数据,形成新一代信息通信的新应用模式.近年来国内外网络安全态势越发严峻,关键信息基础设施已经成为黑客组织重点攻击的目标,工业互联网的安全保障面临全新挑战.如何建立面向工业互联网安全的保障体系,有效避免工业控制系统及终端设备的内外部攻击,降低工业数据被泄露、篡改等风险,保障工业互联网平台及应用的安全可靠性,这是目前亟待解决的问题.综合分析和介绍了工业互联网的现状、安全风险与密码应用需求及应用现状等;研究并设计了工业互联网密码保障框架,介绍了该框架各组成部分对工业互联网的保障支撑作用和工业互联网密码应用模式、方法及密码应用发展趋势;概要阐述了在工业互联网网络安全、边缘节点安全、控制协议安全中密码应用的关键技术.对加强我国工业互联网密码应用落地与推广、护航工业数字化转型等具有参考价值.关键词工业互联网;数据安全;密码技术;协议安全;身份认证;隐私保护

关键词: 工业互联网, 数据安全, 密码技术, 协议安全, 身份认证, 隐私保护

Abstract: The Industrial Internet is based on the network, takes the platform as the core, and takes security as the guarantee. It connects all industry elements and the entire industry chain through the largescale key network infrastructure, collects, and analyzes industry data in realtime, forming a new application model of nextgeneration ICT(Information Communication Technology). In recent years, the network security situation at home and abroad has become more severe, and critical information infrastructure has increasingly become the target of key attacks by statelevel attackers and hacker organizations. The security assurance of the Industrial Internet will face new challenges. How to establish a security system for industrial Internet, effectively avoid internal and external attacks on industrial control systems and terminal equipment, reduce risks such as industrial data leakage and tampering, and ensure the security and reliability of industrial Internet platforms and applications are urgent problems to be solved. The paper comprehensively analyzes and introduces the status quo of the Industrial Internet, security risks and cryptographic application requirements and status, etc.; researches and designs the industrial Internet cryptographic security framework, and introduces the security from the components of the framework, as well as the modes, methods and development trends of cryptographic applications for the Industrial Internet; outlines the key technologies of cryptography applications in industrial Internet network security, edge node security, and control security. The paper has reference value for strengthening the implementation and promotion of industrial Internet cryptographic applications in my country and escorting the digital transformation of the industry.Key words industrial Internet; data security; cryptography; protocol security; identity authentication; privacy protection

Key words: industrial Internet, data security, cryptography, protocol security, identity authentication, privacy protection