摘要
不同应用环境下敏感信息的数据安全性保护一直是信息安全领域的一个热点问题。特殊环境下,某些业务系统的配置信息、本地数据库及系统运行程序等系统核心数据依然需要存储在客户机上,而此类敏感信息极易受到用户的违法篡改和破坏,因此对其进行有效的数据安全保护十分必要。文章在对传统敏感信息保护研究基础上,通过采用数据加密算法,结合文件状态实时监测与日志审计方式,探索开放环境下的敏感信息安全保护方法,设计了一套能够在线监控用户敏感信息访问的实时监控系统,并通过实验测试了该系统的有效性。
Data security protection of sensitive information in different application environments has always been a hot issue in the field of information security.Especially in some special open environments,the core data of some business systems,such as configuration information,local database and system running program,still need to be stored on the client.Such sensitive information is also vulnerable to illegal tampering and destruction by users,so it is necessary to protect its data security effectively.Based on the research of traditional sensitive information protection,this paper explores the method of sensitive information security protection in open environment by using data encryption algorithm and combining with real-time monitoring of file status and log audit,and designs a real-time monitoring system which can monitor users'sensitive information access online.Finally,the effectiveness of the system is tested by experiments.
出处
《淮南师范学院学报》
2020年第2期128-131,共4页
Journal of Huainan Normal University
基金
安徽高校人文社会科学研究重点项目“面向高校应急管理的大数据分析技术应用研究”(SK2017A0507)。
关键词
敏感信息
数据安全
加密算法
访问控制
sensitive information
data security
encryption algorithms
access control