摘要
根据工业控制系统信息安全的要求以及现有防御措施的技术特点,提出一种基于可信计算的工业控制系统信息安全解决方案,通过工业控制系统内部防火墙、入侵检测系统与可信连接服务器之间的联动验证机制,实现了多个网络安全设备的信息交互,提高了工业控制系统的综合防御能力,并且由于可信平台模块基于硬件加密、存储、控制的保护模式,克服了传统基于纯软件的修堵缝补技术导致易破解的通病,达到显著提升工业控制系统安全性的目的.结合SCADA(supervisory control and data acquisition)系统对所提出的基于可信计算的安全工业控制信息安全系统的工程实施进行了讨论.
An information security solution scheme of industrial control system based on trusted computing is proposed by taking into account the characteristics of information security of industrial control system and the technical features of existing defensive measures. By using the proposed linkage mechanism between the inside firewall of industrial control systems, the intrusion detection system and the trusted connection server, inforumation interaction of network security devices is realized, which improves the overall defense capability of industrial control systems. Because of the protection pattern of trusted platform module based on hardware encryption, storage and control, the proposed solution overcomes the common shortcoming of the traditional pure software that is easily cracked, and this greatly increases security capacity of industrial control system. Finally, the trusted computing based information security solution for industrial control system is discussed by applying to the SCADA ( supervisory control and data acquisition) system.
出处
《信息与控制》
CSCD
北大核心
2015年第5期628-633,640,共7页
Information and Control
基金
国家高技术研究发展计划资助项目(2014AA041802-2)
关键词
工业控制系统
信息安全
可信计算
可信连接
industry control system
information security
trusted computing
trusted connection