刘波+++史春光+++赵文想
【 摘 要 】 论文介绍了可信计算及自主可控的相关概念,并基于可信链传递的原理,针对靶场实际,探讨在自主可控条件下,利用可信计算技术和网络安全技术构建航天靶场安全可控信息环境的思路和方法,通过可信计算和自主可控的有效结合,切实推进国家自主可控战略在航天靶场的落地,提升靶场信息系统的安全防御能力。
【 关键词 】 可信计算;自主可控;可信链;信息环境
【 中图分类号 】 TP309.1
Discussion on the Construction of Safe and Controllable Information Environment in Launch Vehicle Range based on the Autonomous and Controllable Technology and the Trusted Computing Technology
Liu Bo Shi Chun-guang Zhao Wen-xiang
(Taiyuan Satellite Launch Center ShanxiTaiyuan 030027)
【 Abstract 】 This paper introduces the concept of trusted computing and autonomous and controllable. According to the principle of trusted computing, it discusses the ideas and methods of construction safety credible information environment in the Launch Vehicle Range, which use trusted computing technology and network security technology in the autonomous control condition. It can push forward the application of National autonomous control strategy in the Launch Vehicle Range and promote the defensive ability of the information system.
【 Keywords 】 trusted computing;autonomous and controllable;trusted chain;information environment
1 引言
随着靶场信息化建设的推进和各类信息系统的广泛应用,靶场的信息环境面临着越来越严峻的网络安全形势,受国产软硬件信息产品的技术发展水平所限,靶场大量使用国外软硬件产品,尤其是核心芯片、操作系统和数据库等,而这些产品中可能存在内置的后门和漏洞,给靶场的信息环境带来了严重的安全隐患。
可信计算的概念来源于1999年的TCG(Trusted Computing Group),主要思路是在PC机硬件平台上引入安全芯片架构,通过芯片提供的安全特性来提高终端系统的安全性[1]。
基于可信计算技术,采用国产自主可控的信息产品来构建安全可控的信息环境可以从根本上解决信息系统现有的后门、漏洞等问题,克服传统的采用国外软硬件产品易受控制、易被攻击的缺陷,有效地提升靶场信息系统的防御能力,整体提升靶场网络的安全性。
2 可信计算定义及相关技术理论
可信计算技术被认为是最有可能从根本上解决计算机系统安全问……