摘要
为解决交通运输行业信息系统中存在的密码应用不规范、难管理、碎片化、难扩展等问题,提出了商用密码云服务的技术思路。通过分析行业商用密码应用的通用及特性化需求,设计了密码云底层虚拟密码机调度算法和服务基础框架,技术层面以商用密码算法和密码产品为基础,构建了密码资源池,结合云计算技术,设计了虚拟化、弹性化的密码接口及应用,为电子政务、电子证照、车路协同等业务提供了密码服务。按照提出的密码云服务基础架构和虚拟密码机调度算法,搭建了试验环境并进行了性能测试。结果表明:提出的密码云服务基础框架和虚拟密码机调度算法具有实际应用意义,可指导密码使用过程中的产品形态、服务模式、商业模式从本地化向云服务化转型,综合发挥商用密码应用效益,并可为行业商用密码应用安全性评估及监管提供支撑。
In order to solve the problems existing in the information system of transport industry,such as irregular cryptography application,management difficulty,fragmented and difficult to expand,the technical idea of commercial cryptography cloud service is put forward.By analyzing the general and characteristic demands of commercial cryptography applications in the industry,the Virtual Security Module(VSM)scheduling algorithm and the basic framework of cryptography cloud bottom is designed.At the technical level,the cryptography resource pool is constructed based on the commercial cryptography algorithm and cryptography products.Combining with cloud computing technology,the virtual flexible cryptography interface and application are designed,which can provide cryptography services for e-government,electronic license,vehicle-road cooperation and other businesses.According to the basic framework of cryptography cloud service and VSM scheduling algorithm,the experimental environment is built and the performance is tested.The result shows that the proposed basic framework of cryptography cloud service and VSM scheduling algorithm have practical application significance,which can guide the transformation of product form,service mode and business mode from localization to cloud service in the process of cryptography use,give full play to the benefits of commercial cryptography application,and provide support for the security evaluation and supervision of commercial cryptography application in the industry.
作者
王佳宁
王立岩
梅新明
范晨歌
李述胜
WANG Jia-ning;WANG Li-yan;MEI Xin-ming;FAN Chen-ge;LI Shu-sheng(Beijing GOTEC ITS Technology Co.,Ltd.,Beijing 100088,China;Research and Development Center of Transport Industry for Network Security Technologies,Beijing 100088,China;Beijing Certificate Authority Co.,Ltd.,Beijing 100080,China)
出处
《公路交通科技》
CAS
CSCD
北大核心
2022年第S01期136-141,174,共7页
Journal of Highway and Transportation Research and Development
关键词
智能交通
密码云
动态调度
商用密码
云计算
ITS
cryptography cloud
dynamic scheduling
commercial cryptography
cloud computing
作者简介
王佳宁(1993-),男,山东莱阳人.(wjn@itsc.cn)