摘要
随着信息技术的快速发展,网络与信息安全问题越发显著,业务复杂化和攻击常态化等问题日益凸显,因此单一的身份鉴别模式存在身份信息易被窃取、无法防范内部用户违规操作等问题,已不能满足身份认证的安全要求。针对现有认证体制中,认证方式及认证策略设定后无法自适应调整的问题,提出了一种基于综合信任评估的自适应动态认证方法,以持续对终端和用户进行信任分析。基于利用所提方法得到的持续自适应风险与综合信任评估结果,可以动态调整认证策略和认证强度,且调整过程可以自动完成,无需人为干预和控制,能够解决认证策略一旦设定就无法自适应调整的问题,具有安全、方便和高效的优点。
With the rapid development of information technology,the issues of network and information security are becoming more and more prominent,and problems such as business complexity and attacks normalization are increasingly significant.The single identity authentication mode has the problems of identity information theft and the inability to prevent the illegal behavior of internal users,etc.,and can no longer meet the security requirements of identity authentication.To address the problem that the authentication methods and policies cannot be adaptively adjusted after they are set in the existing authentication system,this paper proposes an adaptive dynamic authentication method based on comprehensive trust evaluation in order to continuously conduct trust analysis on terminals and users.Based on the continuous adaptive risk and comprehensive trust evaluation results obtained by utilizing the proposed method,the authentication policy and authentication strength can be dynamically adjusted,and the adjustment process can be completed automatically without human intervention and control,which can solve the problem that authentication policies cannot be adaptively adjusted once they are set,and it has the advantages of security,convenience and high efficiency.
作者
丁文超
韦荻山
薛艳珠
房冬丽
余双波
DING Wenchao;WEI Dishan;XUE Yanzhu;FANG Dongli;YU Shuangbo(No.30 Institute of CETC,Chengdu Sichuan 610041,China;Unit 63921 of PLA,Beijing 100080,China)
出处
《通信技术》
2024年第9期942-948,共7页
Communications Technology
关键词
身份认证
认证策略
信任评估
动态认证
自适应
identity authentication
authentication policy
trust evaluation
dynamic authentication
self-adaption
作者简介
丁文超(1991-),男,硕士,工程师,主要研究方向为网络与信息安全;韦荻山(1978-),男,硕士,助理研究员,主要研究方向为网络与信息安全;薛艳珠(1978-),女,硕士,工程师,主要研究方向为网络与信息安全;房冬丽(1990-),女,硕士,工程师,主要研究方向为网络与信息安全;余双波(1982-),男,硕士,高级工程师,主要研究方向为网络与信息安全。