信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2025, Vol. 51 ›› Issue (1): 46-51.doi: 10.12267/j.issn.2096-5931.2025.01.007

专题:网络安全 上一篇    下一篇

零信任发展与应用研究

Research of zero trust development and application

吴倩琳, 孔松   

  1. 中国信息通信研究院云计算与大数据研究所,北京 100191
  • 收稿日期:2024-07-08 出版日期:2025-01-25 发布日期:2025-02-14
  • 作者简介:
    吴倩琳, 中国信息通信研究院云计算与大数据研究所开源和软件安全部工程师,主要从事零信任相关技术、标准、评估、产业等方面的研究工作;
    孔松, 中国信息通信研究院云计算与大数据研究所开源和软件安全部副主任,工程师,主要从事云安全相关技术、标准、评估、产业等方面的研究工作

WU Qianlin, KONG Song   

  1. Cloud Computing & Big Data Research Institute, China Academy of Information and Communications Technology, Beijing 100191,China
  • Received:2024-07-08 Online:2025-01-25 Published:2025-02-14

摘要:

随着产业数字化进程中安全需求的不断升级,我国零信任发展进程加快。梳理了零信任政策与标准发布情况,研究零信任如何解决企业在身份、终端、网络环境、应用与工作负载、数据、安全管理6个领域面临的安全问题;基于对国内零信任供应侧企业、金融行业应用企业开展的调研结果,形成供应能力图谱,分析零信任应用场景和作用;最后剖析了人工智能如何赋能零信任发展。

关键词: 零信任, 零信任标准, 零信任生态

Abstract:

With the continuous upgrading of security needs in the process of industrial digitization, the development of zero trust in China has accelerated. This paper first reviews the zero trust policies and standards, and studies how zero trust solves the security problems faced by enterprises in the six areas, namely, identity, terminal, network environment, applications and workloads, data, and security management. Then, based on the investigation on the supply-side zero trust enterprises and the application enterprises in the financial industry in China, this paper forms the supply capability mapping and analyzes the application scenarios and roles of zero trust. Finally, it analyzes how artificial intelligence empowers the development of zero trust.

Key words: zero trust, zero trust standard, zero trust ecology

中图分类号: