计算机与现代化 ›› 2023, Vol. 0 ›› Issue (06): 118-126.doi: 10.3969/j.issn.1006-2475.2023.06.019

• 信息安全 • 上一篇    

面向工业互联网平台的商用密码改造

莫严1, 唐容川2, 鞠昊1, 孙绍飞3, 王安3   

  1. 1.徐工汉云技术股份有限公司,江苏 徐州 221000;
    2.北京理工大学计算机学院,北京 100081;
    3.北京理工大学网络空间安全学院,北京 100081
  • 收稿日期:2022-07-11 修回日期:2022-09-05 出版日期:2023-06-28 发布日期:2023-06-28
  • 通讯作者: 王安(1983—),男,山东莱州人,研究员,博士生导师,博士,研究方向:密码学,侧信道分析与防护,密码工程实现与应用,E-mail: wanganl@bit.edu.cn。
  • 作者简介:莫严(1996—),男,江苏泰州人,高级工程师,本科,研究方向:信息系统等级保护应用,工业互联网密码应用,E-mail: m18951632466@163.com; 唐容川,男,研究方向:侧信道攻击与防护,硬件密码安全; 鞠昊,男,研究方向:网络空间安全,工业互联网安全; 孙绍飞,男,博士,研究方向:侧信道分析,人工智能和电磁兼容。
  • 基金资助:
    北京市自然科学基金资助项目(4202070); 国家自然科学基金资助项目(62272047, 61872040, 62002021); 国家重点研发计划项目(2021YFB3101500); 浙江省密码技术重点实验室项目(ZCL21004)

Commercial Cryptographic Upgrade for Industrial Internet Platform

MO Yan1, TANG Rong-chuan2, JU Hao1, SUN Shao-fei3, WANG An3   

  1. 1. XCMG Hanyun Technology Co., Ltd., Xuzhou 221000, China;
    2. School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China;
    3. School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing 100081, China
  • Received:2022-07-11 Revised:2022-09-05 Online:2023-06-28 Published:2023-06-28

摘要: 工业互联网是关键信息基础设施的重要一环, 其信息安全问题至关重要, 商用密码是保障工业互联网信息安全的重要手段。本文提出一种将商用密码应用于汉云工业互联网平台的基本架构, 给出一种对工业互联网平台物理层、基础设施即服务层、平台即服务层、软件即服务层、设备层、控制层进行密码应用升级改造的解决方案, 用于解决信息安全管理方面以及信息安全技术方面的种种安全问题, 并将该架构应用到工业界实际项目的落地过程。该密码应用升级改造架构与汉云工业互联网大数据平台以及徐工重型车联网平台现有业务架构进行对接和改造, 将原平台设备与符合国家有关标准要求的商用密码产品的兼容适配攻关, 实现了对汉云工业互联网大数据平台和徐工重型车联网平台的密码应用升级改造, 展现了该架构的广泛适用性和可持续发展潜力。

关键词: 工业互联网平台, 商用密码, 工控系统, 信息安全

Abstract: Industrial Internet is an important part of key information infrastructure, and its information security is very important. Commercial cryptographic algorithm is an important means to ensure the information security of industrial Internet. In response to these two types of security problems, this paper proposes a basic architecture for applying commercial cryptography to the industrial internet platform, and provides a solution for upgrading and transforming cryptographic applications at physical layer, infrastructure-as-a-service, platform-as-a-service, software-as-a-service, device layer and control layer of the industrial internet platform. It has been widely used to solve various security problems in information security management and information security technology, and the architecture has been applied to the implementation process of actual projects in the industry. The cryptographic application upgrade and transformation framework is connected and reconstructed with the existing business framework of the Hanyun Industrial Internet Big Data Platform and the Xuzhou Construction Machinery Group’s (XCMG) Internet of Vehicles Platform. The compatibility of the original platform equipment and the commercial cryptographic products that meet the requirements of relevant national standards has been achieved. The upgrade and transformation of the cryptographic application of the Hanyun Industrial Internet Big Data Platform and the XCMG Internet of Vehicles Platform has been achieved which demonstrated the broad applicability and sustainable development potential of the architecture.

Key words: industrial internet platform, commercial cryptography, industrial control system, information security

中图分类号: