摘要
[目的/意义]密码是网络信息安全的基础和核心,是国家网络信息建设的重要组成部分.高速联网收费系统作为我国关键信息基础设施重点应用之一,其信息系统数据敏感而且重要,系统运营者应当使用商用密码对系统信息加密保护.[方法/过程]为了构建高速联网收费系统自主、安全、可控的信息技术体系,基于商用密码应用的安全性评估以及国家的相关法律法规文件的要求,针对业务密码管理和密码改造应用,从密码动态管理、物理与环境安全、网络与通信安全、设备与计算安全、应用与数据安全等层面提出改进措施.[结果/结论]分析了当前高速联网收费系统在密码应用过程中存在的问题和风险,通过商用密码技术确保数据安全、网络安全、隐私安全和密码安全,构建了以密码技术为核心的安全体系,建设以密码基础设施为支撑的安全环境,从而为业务系统提供了更加完善的安全服务.
[Purpose/Significance]Password is the foundation and core of network information security and an important part of national network information construction.As one of the important industries of China's critical information infrastructure,the high-speed network charging system has sensitive and important information system data,and system operators should use commercial passwords to encrypt and protect system information.[Method/Process]In order to build an autonomous,secure and controllable information technology system for high-speed network charging system,it is based on the security assessment of commercial cryptography applications and the requirements of relevant national laws and regulations.For business password management and password transformation applications,improvement measures are proposed from several levels,such as password dynamic management,physical and environmental security,network and communication security,device and computing security,application and data security.[Results/Conclusion]This paper analyzes the problems and risks in the current high-speed network charging system in the process of cryptographic application,and ensures data security,network security,privacy security and password security through commercial cryptography technology.Build a security system with cryptography technology as the core and a secure environment supported by cryptographic infrastructure to provide more complete security services for business systems.
作者
蔡冠军
杨文赓
Cai Guanjun;Yang Wengeng(Jiangsu Ningsuxu Expressway Co.,Ltd.,Jiangsu Suqian 223800)
出处
《网络空间安全》
2023年第3期51-60,共10页
Cyberspace Security
关键词
商用密码
信息安全
数据安全
网络安全
密码改造
commercial cryptography
information security
data security
network security
password transformation
作者简介
蔡冠军(1973-),男,汉族,南京大学,本科,江苏宁宿徐高速公路有限公司,高级工程师,主要研究方向和关注领域:高速公路信息化规划、建设与运维、网络安全管理;杨文赓(1985-),男,汉族,淮安信息学院,专科,江苏宁宿徐高速公路有限公司,工程师,主要研究方向和关注领域:高速公路机电系统建设与运维、网络安全管理。