在政务信息化快速发展的背景下,政务云平台的安全性至关重要。本研究基于《证书认证系统密码及其相关安全技术规范》,聚焦政务云的PaaS和IaaS层,通过系统性改造构建了多层次、多模式的密码资源服务体系。在IaaS层,采用专用密码服务器与虚拟化技术,实现分布式密码服务;在PaaS层,基于微服务架构提供SM2、SM3、SM4等综合密码服务,确保数据的完整性、机密性和可用性。结合签名验签、SSL/TLS、电子签章等技术,构建了涵盖传输加密、数据校验、防篡改和抗抵赖的全方位安全体系。研究显著提升了政务云平台的安全性,实现了数据全生命周期的可管理与可控性,为政务云中的敏感信息提供了全方位加密保护。未来,随着商用密码技术的广泛应用和密码产业的快速发展,本研究为政务云平台的安全建设提供了重要参考,并为密码技术的创新与应用指明了方向。
Abstract
Under the backdrop of the rapid development of government informatization, the security of government cloud platforms is of paramount importance. Based on the Technical Specification for Cryptography and Related Security of Certificate Authentication System, this study focuses on the PaaS and IaaS layers of government clouds and constructs a multi-level and multi-mode cryptographic resource service system through systematic transformation. At the IaaS layer, dedicated cryptographic servers and virtualization technology are adopted to achieve distributed cryptographic services. At the PaaS layer, comprehensive cryptographic services such as SM2, SM3, and SM4 are provided based on a microservice architecture to ensure the integrity, confidentiality, and availability of data. By integrating technologies such as signature verification, SSL/TLS, and electronic signatures, a comprehensive security system covering transmission encryption, data verification, tamper-proofing, and non-repudiation is established. This research significantly enhances the security of government cloud platforms, realizes the manageability and controllability of data throughout its lifecycle, and provides all-round encryption protection for sensitive information in government clouds. In the future, with the wide application of commercial cryptography technology and the rapid development of the cryptography industry, this study provides an important reference for the security construction of government cloud platforms and points out the direction for the innovation and application of cryptography technology.
关键词
政务云 /
分布式 /
微服务 /
密码技术
Key words
government cloud /
distributed /
Microservices /
cryptographic technology
{{custom_sec.title}}
{{custom_sec.title}}
{{custom_sec.content}}
参考文献
[1] 倪光南. 坚持信创科技自立自强建设网络强国和数字中国[J].信息安全研究,2021,7(1):2-3.
[2] 廖正赟,石淑英.基于国密商用密码服务的关键信息基础设施安全保障实践[J].信息安全研究,2018,4(5):453-457.
[3] 苏威积,汤敬浩,李剑.一种对称密钥的密钥管理方法及系统[J].信息安全研究,2018,4(1):80-83.
[4] 程子栋. 基于统一密码服务平台的政务信息系统密码应用[J].通讯世界,2024,31(8):34-36.
[5] 陈亚男,李晨旸,刘海峰,等.一种基于密码云的政务云密码应用研究[J].信息安全研究,2020,6(9):844-848.
[6] HUSSEIN N H,KHALID A,KHANFAR K.A Survey of Cryptography Cloud Storage Techniques[J].Journal of Computer Science & Mobile Computing,2016,2(5):186-191.
[7] 屠本伟,杜波,杨维.政务云上应用系统数据存取过程中机密性和完整性的实现[J].网络安全技术与应用,2024(12):62-65.
[8] 陈春燕,赵弘洋,雷鹏炫,等.政务云安全风险分析与监管对策[J].电子质量,2024(2):1-5.
[9] 殷涛,马航,高晨熙.数字政府政务云管理体系建设思路[J].广东通信技术,2023,43(11):2-5.
[10] 掌晓愚,孟茹,钱程.政务云密码服务基础保障体系及关键技术研究[J].信息记录材料,2024,25(6):35-38.
[11] 潘洪波. 政务服务领域统一信息平台的构建与应用[J].中国信息化,2025(11):126-127.
[12] 林庆忠,张燕,李琴.关于政务云运维安全提升方法的探讨[J].电信快报,2025(11):45-48.
[13] 谭世喆. 基于省级政务信创云网络架构优化的研究[J].通信管理与技术,2025(4):25-30.
[14] 胡燕雄,黄彧,徐辉,等.政务专用云平台商用密码应用合规实践[J].信息技术与标准化,2022(5):29-32+78.
[15] 周玮,罗礼晨,魏云涛.信息系统密码应用基本要求标准在政务云场景下的应用[J].信息技术与标准化,2024(S1):26-30.
[16] 彭浩楠,唐明环,查奇文,等.云计算场景商用密码应用研究[J].信息安全研究,2023,9(4):375-381.
[17] 燕杰,樊勇兵,金华敏,等.电信运营商的云计算资源池部署方法概述[J].电信科学,2011,27(10):13-19.
[18] 王珍. 基于混合加密和动态密钥管理的安全传输框架研究[J].网络空间安全,2024,15(3):46-49.
[19] 余祥,杨朋辉,巫岱玥,等.一种面向容器的云数据安全防护模型[C]//中国指挥与控制学会.第九届中国指挥控制大会论文集.国防科技大学;31668部队;78100部队;,2021:5.
[20] 刘云毅,张建敏,冯晓丽,等.5G MEC系统安全能力部署方案[J].电信科学,2022,38(11):143-152.
[21] 张林东,赵勇,王翔宇.商用密码技术标准在云计算场景下的应用实践[J].信息技术与标准化,2024(S1):34-40.
[22] 高志权. 云密码服务关键技术研究[J].数字技术与应用,2019,37(9):181-183.
[23] 王晶,马淑晖.基于身份加密技术的商用密码应用研究[J].中国科技成果,2021,22(13):32-34+42.
[24] Yu R,Wu C,Yan B,et al.Anaysis of the Impact of Big Data on E-commerce in Cloud Computing Environment[J]. Complexity,2021,2021:5613599.
[25] 本刊采编中心.推动我国商用密码事业迈入新时代[J].中国信息安全,2023(7):16.
[26] 张勇. 密码安全的刑法保护[J].法律适用,2022(12):42-52.
[27] 黄昌熙,郑志永,孙雪冬,等.云环境下基于国密算法的密码服务平台建设思路探讨[J].中国新通信,2022,24(8):110-112.