节点文献

Web环境下的MES系统信息安全的研究

Research on Information Security of MES System Based on Web Environment

【作者】 谈诚

【导师】 黄小文;

【作者基本信息】 武汉理工大学 , 机械制造及其自动化, 2008, 硕士

【摘要】 本课题结合武汉理工大学机电工程学院信息化工作室的天工MES系统的开发经验,从阻止系统入侵和入侵检测两个不同的角度,对该MES系统的信息安全隐患及可能的其它外部威胁进行了系统的深入分析。本文提出了Web环境下的MES系统运行的安全目标,并将MES系统安全目标分解成几个可度量的子目标。设计MES系统软件的安全架构方案,着重讨论在确保MES系统安全和高效运行的前提下,利用访问控制机制、防火墙机制以及入侵检测机制,如何将重要数据进行加密保护和入侵防护,从而提高MES系统软件的安全性能和抗攻击能力,提高MES系统的可用性和可靠性。根据国际信息安全标准架构的描述和国内外信息安全系统的策略,提出了Web环境下MES系统软件运行和维护应具有的安全策略。本文系统地介绍了安全架构所采用的VPN技术、Web服务和当前流行的软件安全加密算法等关键技术。筛选了适合MES系统的高效、安全的数据加密算法并付诸实施,并对各种加密解密算法进行了归纳和总结。为了说明该系统安全架构的可用性和安全性,对系统安全架构的部分功能进行模拟实现,对Web环境下的MES系统整体安全性的真实实现进行论述,并给出数据加密解密算法的实现效果图,对入侵检测系统的功能点和MES系统中基于Web服务的身份验证进行了实现。论文的最后总结了本课题的工作,并对未来的研究方向作了展望。

【Abstract】 The thesis combined the development experience of the Tian Gong MES software of Wuhan University of Technology,Mechanical and electronic engineering college,this thesis analyzed the information security risk and probable other external threat of the MES system.It emphasized on preventing the system from invading and intrusion detection.The thesis presented the security operation target of MES system in the web environment,and decomposed the security target into some measureable sub-targets. The security architecture was designed to keep the MES system from secure.It was specially discussed how to encrypt the valuable data and to prevent the intrusion,and taking advantage of access control mechanism,firewall mechanism and invasion detecting mechanism in order to insure the MES system operate safely and efficiently. Thereby it increased security and ability to counter-attack,enhanced the usability and reliability of MES system.The security strategy about operating and maintaining on MES system in the web environment was formulated in accordance with the description of international information security standard and the strategy of information security system.In this thesis the key technology of a secure architecture was also presented, including VPN,Web Service and encryption algorithm for MES software security.The encryption algorithms were evaluated.To make out the feasibility and security of system security architecture,some functions of the architecture were implemented.Examples were given to show the implementation of MES system total security in the web environment,and present achievements of data encryption and decryption algorithm,the implementation of intrusion detection system function and authentication based web service in the MES system.In the end,the work was summarized,and the future direction of research projects was presented.

【关键词】 MESWeb安全架构加密
【Key words】 MESWebSecurity architectureEncryption
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】190
节点文献中: 

本文链接的文献网络图示:

本文的引文网络