信息安全研究 ›› 2026, Vol. 12 ›› Issue (2): 189-.

• 技术应用 • 上一篇    

基于零信任架构的港口工控系统设计

马贺荣1孙松林2   

  1. 1(烟台港股份有限公司山东烟台264099)
    2(北京邮电大学北京100876)
  • 出版日期:2026-02-07 发布日期:2026-01-28
  • 通讯作者: 马贺荣 高级工程师.主要研究方向为工控系统设计、人工智能. 1094368836@qq.com
  • 作者简介:马贺荣 高级工程师.主要研究方向为工控系统设计、人工智能. 1094368836@qq.com 孙松林 博士,教授,博士生导师.主要研究方向为无线通信、视频编解码、信息安全. slsun@bupt.edu.cn

Design of a Port Industrial Control System Based on Zero Trust Architecture

Ma Herong1 and Sun Songlin2   

  1. 1(Yantai Port Co., Ltd., Yantai, Shandong 264099)
    2(Beijing University of Posts and Telecommunications, Beijing 100876)
  • Online:2026-02-07 Published:2026-01-28

摘要: 随着港口工业控制系统向智能化方向不断演进,传统基于边界的安全模型在攻击面扩大、权限管理僵化等方面面临严峻挑战.提出一种基于零信任架构的港口工控系统安全防护方案,融合动态信任评估、软件定义边界(softwaredefined perimeter, SDP)及微隔离等技术,构建分层协同的防御体系.核心工作包括设计“终端—接入—控制—数据”4层防护架构,提出融合身份认证、设备健康度与行为特征的动态信任评估模型,并实现工业协议指令级的细粒度访问控制.实验结果表明,该方案能够将攻击面暴露率从100%降低至8%,平均认证时间缩短至0.8s,权限调整响应时间控制在45s以内,显著提升了港口工控系统的安全防护能力与实时运行性能.

关键词: 零信任, 港口工控系统, 动态访问控制, 微隔离, 软件定义边界, 工业协议安全

Abstract: With the increasing intelligence of port industrial control system (ICS), traditional perimeterbased security models face severe challenges such as expanded attack surfaces and rigid permission management. This paper presents a zero trust architecture (ZTA)based security protection scheme for port ICS, establishing a hierarchical defense system through dynamic trust evaluation, softwaredefined perimeter (SDP), and microsegmentation technologies. The core contributions include a fourlayer architecture (terminal, access, control, and data), a dynamic trust evaluation model that integrates identity authentication, device health, and behavioral characteristics, and finegrained instructionlevel access control for industrial protocols. Experimental results demonstrate that the proposed architecture reduces the attack surface exposure rate from 100% to 8%, optimizes the average authentication time to 0.8s, and limits the permission adjustment response time to 45s, significantly enhancing both security and realtime performance in port industrial control systems.

Key words: zero trust, port industrial control system, dynamic access control, microsegmentation, softwaredefined perimeter, industrial protocol security

中图分类号: