期刊文献+

一种基于DNS的零信任增强认证系统设计

Design of DNS based Zero Trust enhanced authentication system
下载PDF
导出
摘要 针对当前大量HTTPS应用复用证书存在安全风险问题,借鉴了零信任模型中安全策略动态授权的思路,提出了一种基于现有互联网基础设施DNS来扩展增强认证功能的方案,通过在现有DNS权威服务器上额外配置增强的认证信息来对HTTPS访问请求进行动态认证,从而能实时验证当前HTTPS证书的安全状态。该方案通过可信易得的DNS基础设施解决了当前普遍存在的HTTPS证书复用带来的安全问题,是一种灵活高效并且可扩展的零信任安全增强认证架构。 The article addresses the security risks associated with the widespread reuse of certificates in current HTTPS applications.Drawing on the idea of dynamic authorization of security policies in the Zero Trust model,it proposes a solution that enhances authentication capabilities by leveraging the existing Internet infrastructure,specifically DNS.This solution involves dynamically authenticating HTTPS access requests by adding enhanced authentication information to existing DNS authoritative servers.By doing so,it enables real-time validation of the security status of current HTTPS certificates.This approach effectively tackles the security issues arising from the common practice of certificate reuse in HTTPS,utilizing the trusted and readily available DNS infrastructure.It represents a flexible,efficient,and scalable Zero Trust security enhancement authentication framework.
作者 邹立刚 张逸凡 张新跃 袁建廷 Zou Ligang;Zhang Yifan;Zhang Xinyue;Yuan Jianting(Beijing Guoke Cloud Computing Technology Co.,Ltd.,Beijing 100190,China;China Internet Network Information Center,Beijing 100190,China;School of Information Science and Engineering,Xinjiang University,Unumqi 830046,China)
出处 《网络安全与数据治理》 2024年第7期21-25,共5页 CYBER SECURITY AND DATA GOVERNANCE
基金 科技部重点研发专项项目(2022YFB3103000)。
关键词 HTTPS 证书 零信任安全模型 DNS DSN-CA HTTPS certificate Zero Trust Security Model DNS DNS-CA
  • 相关文献

参考文献13

二级参考文献88

  • 1马佳乐,郭银章.云计算用户行为信任评估与访问控制策略研究[J].计算机应用研究,2020,37(S02):260-262. 被引量:9
  • 2FreeSWan Projects.FreeSWan1.97 open source code[EB/02].http://www.freeswan.org.2002.
  • 3史伟奇.PKI技术的应用缺陷研究[J].中国人民公安大学学报(自然科学版),2007,13(3):53-56. 被引量:5
  • 4PaulAlbits CricketLiu 雷迎春 陈世林 杨传军译.DNS与BIND[M].北京:中国电力出版社,2001.200-203.
  • 5E - Soft Inc. Secure server survey [ EB / OL ] . http : / / www. securi tyspace, com/s_survey/sdata/2OOSOS/certca.html, August 2005.
  • 6VeriSign Inc. Verisign international server ca-class 3 crl[ EB/OL].http://crl. verisign.com/Class3IntetnationalServer.crl,July 2005.
  • 7GeoTrust Inc. Equifax secure certificate authoritycrl [ EB / OL ] . http://crl.geotrust.com/crls/secureca.crl, July 2005.
  • 8Thawte Consulting Ltd. Thawte server ca crl [ EB / OL ] . https : / /www. thawte.com/cgi/lifecycle/ThawteServerCA.crl, July 2005.
  • 9Entrust Inc. Entrust SSL Web Server Certificate Practice Statement[ EB/OL ]. http://www.entrust.com/ssl-certificates/CPS/pdf/webcps112803.pdf, November 2003.
  • 10HOUSLEY R, POLK W, FORD W, et al. Internet x. 509 public key infrastructure: Certificate and certificate revocation list(crl) profile[ S]. RFC3280, IETF, http://www.ieff. org/rfc/rfc3280.txt? number =3280, April 2002.

共引文献65

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部