摘要
铁路综合视频监控系统是保障铁路行车安全、稳定运行的重要手段,也是国家级网络对抗中的重点攻击目标。铁路综合视频监控系统建设了以网络隔离与边界防护为主的网络安全防护体系,但在面对新型技术手段攻击时,存在防护滞后于攻击、安全制约于业务、防护影响实时性等问题。针对铁路综合视频监控系统安全性的迫切需求,研究基于可信计算的安全解决方案,并从功能及架构角度对方案进行详细完整的分析与设计,确保方案切实可行。通过引入可信计算度量评价体系,参照既有铁路综合视频监控系统组织架构建立可信度量/验证机制,搭建分布式分级可信计算安全平台,通过融合既有视频节点,在保证业务功能不变的前提下,增强其整体安全性,建立具有安全免疫力的可信铁路综合视频监控系统。
The railway integrated video surveillance system is an important means to ensure the safe and stable operation of railway,and is also a key attack target in national network confrontation.The railway integrated video surveillance system has built a network security protection system focusing on network isolation and boundary protection.However,in the face of attacks by new technical means,there are problems such as protection lagging behind attacks,security restricted by services,and protection affecting real-time performance.In view of the urgent need for the security of railway integrated video surveillance system,the security solution based on trusted computing is studied,and the scheme is analyzed and designed in detail and completely from the perspective of function and architecture to ensure that the scheme is feasible.A trusted measurement/authentication mechanism is established and a distributed hierarchical trusted computing security platform is built by introducing the trusted computing measurement and evaluation system and with reference to the organizational structure of the existing railway integrated video surveillance system.Through the integration of existing video nodes,on the premise of ensuring the same business functions,the overall security is enhanced,and a trusted railway integrated video surveillance system with security immunity is established.
作者
温桂玉
WEN Guiyu(Security System Department,Beijing Jingwei Information Technology Co.,Ltd.,Beijing 100081,China)
出处
《中国铁路》
2022年第12期122-128,共7页
China Railway
基金
中国国家铁路集团有限公司科技研究开发计划项目(K2020W002)。
关键词
铁路综合视频监控系统
可信计算
安全平台
安全免疫
网络安全
railway integrated video surveillance system
trusted computing
security platform
security immunity
network security