运用虚拟桌面技术实现跨网络边界的安全访问
2021-03-08龚伟
龚伟



摘 要:随着网络安全被提升到国家战略,企业逐步开始对信息网络进行边界隔离改造,划分不同网络区域,因此带来了隔离网络间系统访问、用户管理的挑战。本文采用虚拟桌面技术,研究规划在多个隔离网络边界环境下,实现跨网络边界安全访问的可行性。经企业环境推广验证,本文所研究的方法能够使企业实现统一管理、按需交付的跨网络边界安全访问平台。文中所涉及的方法和技术,可以为企业在网络安全加固保护、信息安全和用户管理层面提供全新的思路,提升企业信息安全水平。
关键词:虚拟桌面;网络边界;安全访问;身份鉴别
中图分类号:TP309.1 文献标识码:A
文章编号:2096-1472(2021)-01-32-03
Abstract: As network security has been promoted as a national strategy, enterprises gradually begin to transform information network boundary isolation and divide different network areas. This brings challenges to isolating system access between networks and user management. This paper uses virtual desktop technology to study feasibility of achieving secure access across network boundaries in multiple isolated network boundary environment. Proved by enterprise environment promotion, the proposed method can realize unified management for enterprises and a secure access platform across network boundaries, that is delivered on demand. Methods and technologies involved in this article can provide enterprises with new ideas in network security reinforcement protection, information security and user management levels, and improve the level of enterprise information security.
Keywords: virtual desktop; network boundary; secure access; identity authentication
1 引言(Introduction)
大型企業信息化建设中,为了确保信息系统安全性,通常会将信息化网络拆分为多个专用网络,从而形成边界隔离的网络环境,不同边界间使用防火墙、网闸或者物理隔离的方式,实现访问控制和安全策略管理[1,2]。但企业计算机设备、应用系统一般仅允许连接到一个网络区域中,员工无法使用单一终端接入多个网络,使用不同网络中的应用系统[3]。传统情况下企业会为用户配置多个终端,然后使用键盘显示器鼠标(Keyboard Video Mouse, KVM)切换器进行多计算机统一控制[4],但此种方式存在成本高昂、难以管理、易形成安全风险的问题。随着虚拟桌面技术不断成熟,终端、用户、桌面分离管理,后台统一配置交付的技术方案,为企业实现跨网络边界安全访问提供了富有价值的解决方案。……
