Cholinga chachitetezo ndi data yomwe imafalitsidwa kudzera pa intaneti yomwe ikugwira ntchito mumanetiweki a data omangidwa pamaziko a stack ya TCP / IP.
"Nfundo zapakatikati" - zinthu za netiweki yotumizira ma data: ma routers, ma switch, ma seva olowera, ma seva a proxy ndi zida zina - momwe magalimoto olumikizira netiweki amafalikira. Nthawi zambiri, kulumikizana kwa intaneti kumatha kugwira ntchito popanda ma node apakatikati (mwachindunji pakati pa ma node omaliza).
Zowopsa zachitetezo chapamwamba
Kuwola
U1. Kufikira kosaloledwa kwa data yotumizidwa.
U2. Kusintha kosavomerezeka kwa data yotumizidwa.
U3. Kuphwanya mlembi wa data yotumizidwa.
U1. Kufikira kosaloledwa kwa data yotumizidwa
Kuwola
U1.1. <β¦>, zomwe zimachitika pomaliza kapena apakatikati:
U1.1.1. <β¦> powerenga deta ili m'zida zosungiramo:
U1.1.1.1. <β¦> mu RAM. Kufotokozera kwa U1.1.1.1.
Mwachitsanzo, pakukonza deta ndi stack network network.
U1.1.1.2. <β¦> mu kukumbukira kosasunthika. Kufotokozera kwa U1.1.1.2.
Mwachitsanzo, posungira deta yotumizidwa mu cache, mafayilo osakhalitsa kapena kusinthana mafayilo.
U1.2. <β¦>, zomwe zimachitika pagulu lachitatu la netiweki ya data:
U1.2.1. <...> ndi njira yojambulira mapaketi onse omwe akufika pa intaneti ya wolandila: Kufotokozera kwa U1.2.1.
Kujambula mapaketi onse kumachitika ndikusintha khadi yamaneti kukhala yachiwerewere (mawonekedwe achiwerewere a ma adapter a waya kapena kuwunika kwa ma adapter a Wi-Fi).
Kuwola
U2.1. <β¦>, zomwe zimachitika pomaliza kapena apakatikati:
U2.1.1. <β¦> powerenga ndikusintha zomwe zili muzosungirako za node:
U2.1.1.1. <β¦> mu RAM:
U2.1.1.2. <β¦> mu kukumbukira kosasunthika:
U2.2. <β¦>, zomwe zimachitika pagulu lachitatu la network yotumizira ma data:
U2.2.1. <β¦> pochita ziwopsezo za munthu wapakati (MiTM) ndikuwongolera magalimoto kumalo omwe akuwukirawo:
U2.2.1.1. Kulumikizana kwakuthupi kwa zida za owukira kumapangitsa kuti intaneti iwonongeke.
U2.2.1.2. Kulimbana ndi ma protocol a network:
U2.2.1.2.1. <β¦> kasamalidwe ka ma network apafupi (VLAN):
U2.2.1.2.1.1. Kudumpha kwa VLAN.
U2.2.1.2.1.2. Kusintha kosaloledwa kwa VLAN pa ma switch kapena ma routers.
U2.2.1.2.2. <β¦> njira zamagalimoto:
U2.2.1.2.2.1. Kusintha kosaloledwa kwa ma static routing tables a ma routers.
U2.2.1.2.2.2. Kulengeza kwa njira zabodza ndi omwe akuwukira kudzera mumayendedwe osinthika.
U2.2.1.2.3. <β¦> kasinthidwe kake:
U2.2.1.2.3.1. DHCP yamphamvu.
U2.2.1.2.3.2. WPAD yamphamvu.
U2.2.1.2.4. <β¦> adilesi ndi kukonza dzina:
U2.2.1.2.4.1. Kusintha kwa ARP.
U2.2.1.2.4.2. Kuwonongeka kwa DNS.
U2.2.1.2.4.3. Kupanga zosintha zosaloleka pamafayilo am'malo am'malo (makamu, lmhosts, ndi zina)
U3. Kuphwanya ufulu wazinthu zotumizidwa
Kuwola
U3.1. Kusalowerera ndale kwa njira zodziwira kulembetsedwa kwa chidziwitso powonetsa zabodza zokhudza wolemba kapena gwero la data:
U3.1.1. Kusintha zambiri za wolemba zomwe zili muzomwe zimafalitsidwa.
U3.1.1.1. Kusalowerera ndale kwa chitetezo cha cryptographic cha kukhulupirika ndi kulembedwa kwa data yofalitsidwa:
U3.1.1.1.1. Ulalo: "Chitsanzo chowopsa. Cryptographic information chitetezo system.
U4. Kupanga siginecha yamagetsi ya wosayina wovomerezeka pansi pazabodza".
U3.1.1.2. Kusalowerera ndale kwa kutetezedwa kwa copyright kwa data yofalitsidwa, kukhazikitsidwa pogwiritsa ntchito ma code otsimikizira kamodzi:
U3.1.1.2.1. Kusintha kwa SIM.
Cholinga cha chitetezo ndi dongosolo lachidziwitso lomangidwa pamaziko a zomangamanga za kasitomala-server.
zomangamanga
Kufotokozera za zomangamanga:
"Kasitomala" - chipangizo chomwe gawo la kasitomala la chidziwitso limagwira ntchito.
"Seva" - chipangizo chomwe gawo la seva lachidziwitso limagwira ntchito.
"Data store" - gawo lachitukuko cha seva ya dongosolo la chidziwitso, lopangidwa kuti lisunge deta yokonzedwa ndi chidziwitso.
"Network connection" - njira yosinthira zidziwitso pakati pa kasitomala ndi Seva yodutsa pa netiweki ya data. Kufotokozera mwatsatanetsatane kwa element element kumaperekedwa "Chitsanzo chowopsa. Kulumikizana kwa netiweki".
Wogwiritsa ntchito amalumikizana ndi dongosolo lazidziwitso mkati mwa nthawi yomaliza, yotchedwa magawo a ntchito.
Kumayambiriro kwa gawo lililonse la ntchito, wogwiritsa ntchito amadziwika, amatsimikiziridwa ndi kuvomerezedwa.
Zidziwitso zonse zotetezedwa zimasungidwa pagawo la seva la chidziwitso.
Zowopsa zachitetezo chapamwamba
Kuwola
U1. Kuchita zosaloledwa ndi omwe akuukira m'malo mwa ogwiritsa ntchito ovomerezeka.
U2. Kusintha kosavomerezeka kwa chidziwitso chotetezedwa panthawi yomwe ikukonzedwa ndi gawo la seva la chidziwitso.
U1. Kuchita zosaloledwa ndi omwe akuukira m'malo mwa ogwiritsa ntchito ovomerezeka
U1.1.9.5. Owukirawo adalanda zomwe zidachokera pa kiyibodi pogwiritsa ntchito
kusanthula kwa siginecha ya Wi-Fi yosinthidwa ndi njira ya wosuta. Kufotokozera U1.1.9.5.
Chitsanzo: kuwukira.
U1.1.9.6. Owukirawo adasokoneza kulowetsa kwa zizindikiro kuchokera pa kiyibodi posanthula phokoso la makiyi. Kufotokozera U1.1.9.6.
Chitsanzo: kuwukira.
U1.1.9.7. Owukirawo adasokoneza kulowa kwa zidziwitso kuchokera pa kiyibodi ya foni yam'manja posanthula zowerengera za accelerometer. Kufotokozera U1.1.9.7.
Chitsanzo: kuwukira.
U1.1.10. <β¦>, idasungidwa kale pa Makasitomala. Kufotokozera U1.1.10.
Mwachitsanzo, wogwiritsa ntchito amatha kusunga malowedwe ndi mawu achinsinsi mu msakatuli kuti alowe patsamba linalake.
Integration module ndi gulu lazinthu zopangira zidziwitso zomwe zidapangidwa kuti zithandizire kusinthana kwa chidziwitso pakati pa machitidwe azidziwitso.
Poganizira kuti m'magulu amakampani sikutheka nthawi zonse kulekanitsa dongosolo lachidziwitso chimodzi kuchokera ku lina, gawo lophatikizana lingathenso kuonedwa ngati kugwirizana pakati pa zigawo zomwe zili mkati mwa chidziwitso chimodzi.
zomangamanga
Chithunzi chokhazikika cha module yophatikiza chikuwoneka motere:
Kufotokozera za zomangamanga:
"Exchange Server (SO)" - node / ntchito / gawo lachidziwitso chomwe chimagwira ntchito yosinthanitsa deta ndi chidziwitso china.
"Mkhalapakati" - node / ntchito yokonzedwa kuti ikonzekere kuyanjana pakati pa machitidwe azidziwitso, koma osati gawo lawo.
Zitsanzo "Akhalapakati" pakhoza kukhala ma imelo, mabasi ogwira ntchito zamabizinesi (mabasi ochitira bizinesi / zomangamanga za SoA), ma seva amtundu wachitatu, ndi zina zambiri. Kawirikawiri, gawo lophatikizana silingakhale ndi "Intermediaries".
"Deta processing software" - mndandanda wa mapulogalamu omwe amagwiritsira ntchito ndondomeko zosinthira deta ndikusintha mawonekedwe.
Mwachitsanzo, kutembenuza deta kuchokera ku mtundu wa UFEBS kupita ku mtundu wa ABS, kusintha masitepe a mauthenga panthawi yotumizira, ndi zina zotero.
"Network connection" zimagwirizana ndi chinthu chofotokozedwa mu "Network connection" yowopsyeza chitsanzo. Malumikizidwe ena a netiweki omwe akuwonetsedwa pachithunzi pamwambapa mwina kulibe.
Zitsanzo za ma module ophatikiza
Chiwembu 1. Kuphatikiza kwa ABS ndi AWS KBR kudzera pa seva ya fayilo ya gulu lina
Kuti alipire, wogwira ntchito ku banki wovomerezeka amatsitsa zikalata zolipirira pakompyuta kuchokera kumabanki oyambira ndikuzisunga ku fayilo (mumtundu wake, mwachitsanzo, kutaya kwa SQL) pafoda ya netiweki (...SHARE) pa seva yamafayilo. Kenako fayiloyi imasinthidwa pogwiritsa ntchito chosinthira kukhala mafayilo amtundu wa UFEBS, omwe amawerengedwa ndi malo ogwirira ntchito a CBD.
Pambuyo pake, wogwira ntchito wovomerezeka - wogwiritsa ntchito malo ogwirira ntchito a KBR - amalembera ndi kusaina mafayilo omwe adalandira ndikuwatumiza ku Bank of Russia.
Ndalama zikalandiridwa kuchokera ku Bank of Russia, malo ogwirira ntchito a KBR amawachotsa ndikuwunika siginecha yamagetsi, pambuyo pake imawalemba m'mafayilo amtundu wa UFEBS pa seva yamafayilo. Asanalowetse zikalata zolipirira ku ABS, amasinthidwa pogwiritsa ntchito cholembera kuchokera ku mtundu wa UFEBS kupita ku mtundu wa ABS.
Tidzaganiza kuti mu chiwembu ichi, ABS imagwira ntchito pa seva imodzi yakuthupi, malo ogwirira ntchito a KBR amagwira ntchito pakompyuta yodzipatulira, ndipo cholembera chosinthira chimayenda pa seva yamafayilo.
Kulumikizana kwa zinthu zachithunzichi zomwe zimaganiziridwa pazinthu zamtundu wophatikiza: "Sinthani seva kuchokera ku mbali ya ABS" - ABS seva. "Sinthani seva kuchokera ku mbali ya AWS KBR" - makina apakompyuta a KBR. "Mkhalapakati" - seva ya fayilo yachitatu. "Deta processing software" - Converter script.
Scheme 2. Kuphatikiza kwa ABS ndi AWS KBR poyika foda ya netiweki yogawana ndi zolipira pa AWS KBR
Chilichonse chiri chofanana ndi Scheme 1, koma seva yosiyana ya fayilo sikugwiritsidwa ntchito; m'malo mwake, foda ya intaneti (...GAWANI) yokhala ndi zikalata zolipira zamagetsi imayikidwa pa kompyuta ndi ntchito ya CBD. Zolemba zosinthira zimagwiranso ntchito pa CBD workstation.
Kulumikizana kwa zinthu zachithunzichi zomwe zimaganiziridwa pazinthu zamtundu wophatikiza:
Zofanana ndi Scheme 1, koma "Mkhalapakati" osagwiritsidwa ntchito.
Scheme 3. Kuphatikiza kwa ABS ndi malo ogwirira ntchito KBR-N kudzera pa IBM WebSphera MQ ndi kusaina zikalata zamagetsi "mbali ya ABS"
ABS imagwira ntchito pa pulatifomu yomwe siyikuthandizidwa ndi Siginecha ya CIPF SCAD. Kusaina kwa zikalata zamagetsi zomwe zikutuluka kumachitika pa seva yapadera ya siginecha yamagetsi (ES Server). Seva yomweyo imayang'ana siginecha yamagetsi pazolemba zomwe zimachokera ku Bank of Russia.
ABS imakweza fayilo yokhala ndi zikalata zolipira mumtundu wake ku ES Server.
Seva ya ES, pogwiritsa ntchito script converter, imasintha fayilo kukhala mauthenga apakompyuta mumtundu wa UFEBS, pambuyo pake mauthenga apakompyuta amasindikizidwa ndikutumizidwa ku IBM WebSphere MQ.
Malo ogwirira ntchito a KBR-N amafikira ku IBM WebSphere MQ ndikulandila mauthenga olipira omwe asainidwa kuchokera pamenepo, pambuyo pake wogwira ntchito wovomerezeka - wogwiritsa ntchito KBR workstation - amawalembera ndikuwatumiza ku Bank of Russia.
Ndalama zikalandiridwa kuchokera ku Bank of Russia, malo ogwirira ntchito a KBR-N amawachotsa ndikutsimikizira siginecha yamagetsi. Ndalama zomwe zasinthidwa bwino ngati mauthenga a pakompyuta osiyidwa komanso osayinidwa mumtundu wa UFEBS amasamutsidwa kupita ku IBM WebSphere MQ, kuchokera komwe amalandiridwa ndi Electronic Signature Server.
Seva ya siginecha yamagetsi imatsimikizira siginecha yamagetsi yamalipiro omwe adalandilidwa ndikusunga mufayilo mumtundu wa ABS. Pambuyo pake, wogwira ntchito wovomerezeka - wogwiritsa ntchito ABS - amatsitsa fayiloyo ku ABS m'njira yovomerezeka.
Kulumikizana kwa zinthu zachithunzichi zomwe zimaganiziridwa pazinthu zamtundu wophatikiza: "Sinthani seva kuchokera ku mbali ya ABS" - ABS seva. "Sinthani seva kuchokera ku mbali ya AWS KBR" - makina apakompyuta a KBR. "Mkhalapakati" - Seva ya ES ndi IBM WebSphere MQ. "Deta processing software" - script converter, CIPF SCAD Signature pa ES Server.
Scheme 4. Kuphatikiza kwa RBS Server ndi core banking system kudzera pa API yoperekedwa ndi seva yosinthana yodzipereka.
Tiganiza kuti banki imagwiritsa ntchito njira zingapo zamabanki akutali (RBS):
Pofuna kuonetsetsa chitetezo chazidziwitso, kuyanjana konse pakati pa ABS ndi machitidwe amabanki akutali kumachitika kudzera pa seva yodzipatulira yosinthana yomwe ikugwira ntchito mkati mwa dongosolo la chidziwitso cha ABS.
Kenako, tikambirana njira yolumikizirana pakati pa dongosolo la RBS la IKB LE ndi ABS.
Seva ya RBS, italandira chilolezo chovomerezeka chovomerezeka kuchokera kwa kasitomala, iyenera kupanga chikalata chofananira mu ABS potengera izo. Kuti muchite izi, pogwiritsa ntchito API, imatumiza chidziwitso ku seva yosinthira, yomwe imalowetsamo deta mu ABS.
Pamene miyeso ya akaunti ya kasitomala ikusintha, ABS imapanga zidziwitso zamagetsi, zomwe zimatumizidwa ku seva yakutali yakubanki pogwiritsa ntchito seva yosinthanitsa.
Kulumikizana kwa zinthu zachithunzichi zomwe zimaganiziridwa pazinthu zamtundu wophatikiza: "Sinthani seva kuchokera kumbali ya RBS" - Seva ya RBS ya IKB YUL. "Sinthani seva kuchokera ku mbali ya ABS" - seva yosinthira. "Mkhalapakati" - palibe. "Deta processing software" - Zigawo za RBS Server zomwe zimagwiritsa ntchito API ya seva yosinthira, zigawo za seva zomwe zimagwiritsidwa ntchito pogwiritsira ntchito API yaikulu ya banki.
Zowopsa zachitetezo chapamwamba
Kuwola
U1. Kulowetsa kwa zidziwitso zabodza ndi owukira kudzera mugawo lophatikiza.
U1. Kulowetsedwa kwa zidziwitso zabodza ndi owukira kudzera mugawo lophatikiza
Ma Cryptographic primitives amaphatikiza ntchito zotsika kwambiri, monga:
encrypt/decrypt chipika cha data;
pangani / kutsimikizira siginecha yamagetsi ya block block;
kuwerengera ntchito ya hashi ya block block;
kupanga / katundu / kukweza mfundo zazikulu;
ndi zina zotero.
Malingaliro abizinesi a pulogalamu yogwiritsira ntchito amagwiritsa ntchito magwiridwe antchito apamwamba kwambiri pogwiritsa ntchito zilembo za cryptographic:
encrypt fayilo pogwiritsa ntchito makiyi a omwe asankhidwa;
kukhazikitsa maukonde otetezedwa;
dziwitsani za zotsatira za kuyang'ana siginecha yamagetsi;
ndi zina zotero
Kulumikizana kwamalingaliro abizinesi ndi crypto core zitha kuchitika:
mwachindunji, ndi malingaliro abizinesi oyitanitsa zoyamba za cryptographic kuchokera ku malaibulale osinthika a crypto kernel (.DLL ya Windows, .SO ya Linux);
mwachindunji, kudzera mu cryptographic interfaces - wrappers, mwachitsanzo, MS Crypto API, Java Cryptography Architecture, PKCS # 11, ndi zina zotero. Pankhaniyi, malingaliro amalonda amapeza mawonekedwe a crypto, ndipo amamasulira kuyitana kwa crypto core yofanana, yomwe mu mlanduwu umatchedwa crypto provider. Kugwiritsiridwa ntchito kwa cryptographic interfaces kumapangitsa kuti pulogalamu ya pulogalamuyo isasokonezeke ndi ma cryptographic algorithms ndikukhala osinthika.
Gawo loyamba, pamodzi ndi mapulogalamu ogwiritsira ntchito, limagwira ntchito m'malo osadalirika pomwe pali chiopsezo chotenga kachilombo ka code yoyipa. Tidzatcha gawoli "gawo la pulogalamu".
Gawo lachiwiri limagwira ntchito pamalo odalirika pa chipangizo chodzipatulira, chomwe chili ndi zosungirako zachinsinsi. Kuyambira tsopano tidzatcha gawoli "hardware".
Kugawika kwa crypto core kukhala mapulogalamu ndi zida za hardware ndizosamveka. Pali machitidwe pamsika omwe amamangidwa molingana ndi chiwembu chokhala ndi crypto core, koma gawo la "hardware" lomwe limaperekedwa ngati chithunzi cha makina - pafupifupi HSM (chitsanzo).
Kuyanjana kwa mbali zonse ziwiri za crypto core kumachitika m'njira yoti makiyi achinsinsi achinsinsi samasamutsidwa ku gawo la pulogalamuyo ndipo, motero, sangathe kubedwa pogwiritsa ntchito code yoyipa.
Mawonekedwe olumikizirana (API) ndi seti ya cryptographic primitives yoperekedwa ku pulogalamu yogwiritsira ntchito ndi crypto core ndizofanana muzochitika zonsezi. Kusiyana kwagona m'mene amagwiritsidwira ntchito.
Chifukwa chake, mukamagwiritsa ntchito chiwembu chokhala ndi crypto core, kuyanjana kwa mapulogalamu ndi ma hardware kumachitika molingana ndi mfundo iyi:
Ma Cryptographic primitives omwe safuna kugwiritsa ntchito kiyi yachinsinsi (mwachitsanzo, kuwerengera ntchito ya hashi, kutsimikizira siginecha yamagetsi, ndi zina zotero) amachitidwa ndi pulogalamuyo.
Ma Cryptographic primitives omwe amagwiritsa ntchito kiyi yachinsinsi (kupanga siginecha yamagetsi, decrypting data, etc.) amachitidwa ndi hardware.
Gawo la pulogalamuyo limawerengera ntchito ya hashi ya data yosainidwa ndikutumiza mtengowu ku hardware kudzera pa njira yosinthira pakati pa crypto cores.
Gawo la hardware, pogwiritsa ntchito kiyi yachinsinsi ndi hashi, limapanga mtengo wa siginecha yamagetsi ndikuyitumiza ku gawo la mapulogalamu kudzera pa njira yosinthira.
Gawo la pulogalamuyo limabweza mtengo womwe walandilidwa ku pulogalamu yofunsira.
Mawonekedwe akuwona kulondola kwa siginecha yamagetsi
Gawo 1. Kulamulira kukhulupirika kwa deta ndi kulemba deta.
Zamkatimu siteji. Siginecha yamagetsi ya datayo imatsimikiziridwa pogwiritsa ntchito njira yoyenera ya cryptographic algorithm. Kumaliza bwino kwa gawoli kukuwonetsa kuti deta siinasinthidwe kuyambira pomwe idasainidwa, komanso kuti siginecha idapangidwa ndi kiyi yachinsinsi yomwe ikugwirizana ndi kiyi yapagulu yotsimikizira siginecha yamagetsi. Malo a siteji: crypto core.
Gawo 2. Kulamulira kwa chikhulupiliro mu fungulo la anthu osayina ndi kulamulira kwa nthawi yovomerezeka yachinsinsi chachinsinsi cha siginecha yamagetsi. Zamkatimu siteji. Gawoli lili ndi magawo awiri apakatikati. Choyamba ndikuzindikira ngati kiyi yapagulu yotsimikizira siginecha yamagetsi idadaliridwa panthawi yosayina deta. Yachiwiri imatsimikizira ngati kiyi yachinsinsi ya siginecha yamagetsi inali yovomerezeka panthawi yosayina deta. Nthawi zambiri, nthawi zovomerezeka za makiyiwa sizingafanane (mwachitsanzo, paziphaso zoyenerera zamakiyi otsimikizira siginecha yamagetsi). Njira zokhazikitsira kukhulupilika kwa makiyi a anthu osayinawo zimatsimikiziridwa ndi malamulo a kasamalidwe ka zikalata pakompyuta omwe amatengedwa ndi maphwando omwe akukambirana. Malo a siteji: pulogalamu yamapulogalamu / crypto core.
Gawo 3. Kuwongolera ulamuliro wa wosayina. Zamkatimu siteji. Mogwirizana ndi malamulo okhazikitsidwa a kasamalidwe ka zikalata zamagetsi, zimafufuzidwa ngati wosayinayo anali ndi ufulu wotsimikizira deta yotetezedwa. Mwachitsanzo, tiyeni tipereke mkhalidwe wa kuswa ulamuliro. Tiyerekeze kuti pali bungwe lomwe antchito onse ali ndi siginecha yamagetsi. Dongosolo loyang'anira zikalata zamkati mwamagetsi amalandila lamulo kuchokera kwa manejala, koma losainidwa ndi siginecha yamagetsi ya woyang'anira nyumba yosungiramo zinthu. Choncho, chikalata choterocho sichingaganizidwe kuti ndi chovomerezeka. Malo a siteji: pulogalamu yamapulogalamu.
Njira zotumizira zidziwitso, kupatula njira zazikulu zosinthira, zimadutsanso pulogalamu yamapulogalamu, API ndi crypto core.
Zambiri zokhuza kukhulupirira makiyi a anthu onse ndi (kapena) satifiketi, komanso zambiri zamphamvu za eni makiyi a anthu, zili mu sitolo yachinsinsi.
Pulogalamu yogwiritsira ntchito imagwira ntchito ndi sitolo yachinsinsi pagulu kudzera mu crypto kernel.
Chitsanzo cha dongosolo lazidziwitso lotetezedwa pogwiritsa ntchito CIPF
Wogwiritsa ntchito adzayika mafayilo mufoda ya "... Out" yomwe ikufunika kubisidwa, kusaina ndikutumizidwa kwa mnzake. Wogwiritsa ntchitoyo adzikonzekeretsa okha mafayilo pazogwiritsa ntchito.
Kuti mugwiritse ntchito kubisa komanso siginecha yamagetsi, CIPF CryptoPRO, pulogalamu ya CryptoARM ndi kasitomala wa imelo zimayikidwa pamakina enieni. Kuwongolera zokha kwazinthu zonse zamakina owoneka bwino kudzachitika pogwiritsa ntchito zolemba zopangidwa ndi oyang'anira makina. Ntchito ya scripts imalowetsedwa mu mafayilo a log.
Makiyi a Cryptographic a siginecha yamagetsi adzayikidwa pa chizindikiro chokhala ndi kiyi ya JaCarta GOST yosabweza, yomwe wogwiritsa ntchitoyo alumikizane ndi kompyuta yake.
Wotchi yamakina pa malo ogwirira ntchito a wogwiritsa ntchito mu bungwe 1 idzasinthidwa pamanja. Wotchi yamakina odzipatulira mu Organisation 2 idzalumikizidwa ndi wotchi ya hypervisor system, yomwe imalumikizidwa pa intaneti ndi ma seva anthawi yapagulu.
Kuzindikiritsa zinthu zamapangidwe a CIPF
Kutengera ndi zomwe tafotokozazi za zomangamanga za IT, tiwunikira zomwe zidapangidwa ndi CIPF ndikuzilemba patebulo.
Table - Kulumikizana kwa zinthu zachitsanzo za CIPF kuzinthu zamadongosolo azidziwitso
Chuma Bungwe 1 Bungwe 2
Pulogalamu yamapulogalamu
Pulogalamu ya CryptoARM
Pulogalamu ya CryptoARM
U2.2. Kusintha kwa data mu njira yotseguka yosinthira deta. Zolemba za U2.2.
Zitsanzo za kukhazikitsidwa kwa chiwopsezochi zaperekedwa pansipa. apa ΠΈ apa.
U3. Kutsitsidwa kwa data yosungidwa ndi anthu omwe si olandila zovomerezeka (oukira)
U4.2. Kusintha kwa data yomwe yasainidwa munjira yotseguka yosinthira deta. Zindikirani U4.2.
Zitsanzo za kukhazikitsidwa kwa chiwopsezochi zaperekedwa pansipa. apa ΠΈ apa.
U5. Kupeza zotsatira zabwino poyang'ana siginecha yamagetsi ya data yabodza
Kuwola
U5.1. Owukira amatenga uthenga munjira yotumizira zotsatira zantchito zokhudzana ndi zotsatira zoyipa zoyang'ana siginecha yamagetsi ndikuyisintha ndi uthenga wokhala ndi zotsatira zabwino.
U5.2. Zigawenga zimawukira chikhulupiriro pakusaina satifiketi (SCRIPT - zinthu zonse ndizofunikira):
U5.2.1. Zigawenga zimapanga kiyi yapagulu ndi yachinsinsi ya siginecha yamagetsi. Ngati makinawa akugwiritsa ntchito ziphaso za siginecha yamagetsi, ndiye kuti amapanga satifiketi ya siginecha yamagetsi yomwe ili yofanana momwe ingathekere ndi satifiketi ya omwe akufuna kutumiza deta yomwe uthenga wake akufuna kupanga.
U5.2.2. Zigawenga zimapanga kusintha kosaloledwa ku sitolo yachinsinsi ya anthu onse, kupatsa makiyi a anthu kuti apange mlingo wofunikira wa chidaliro ndi ulamuliro.
U5.2.3. Zigawenga zimasaina data yabodza ndi kiyi yosainira yamagetsi yomwe idapangidwa kale ndikuyiyika munjira yotetezeka yosinthira deta.
U5.3. Zigawenga zimachita chiwembu pogwiritsa ntchito makiyi a siginecha apakompyuta omwe atha ntchito a wosayina mwalamulo (SCRIPT - zinthu zonse ndizofunikira):
U5.3.1. Zigawenga zanyengerera makiyi achinsinsi atha ntchito (osati yovomerezeka pakadali pano) a siginecha yamagetsi ya wotumiza wovomerezeka.
U5.3.2. Zigawenga zimalowa m'malo mwa njira yotumizira nthawi ndi nthawi yomwe makiyi owonongeka anali akadali ovomerezeka.
U5.3.3. Zigawenga zimasaina data yabodza ndi kiyi ya siginecha yamagetsi yomwe idasokonezedwa kale ndikuyibaya munjira yotetezeka yosinthira deta.
U5.4. Zigawenga zimawukira pogwiritsa ntchito makiyi osainira osagwirizana ndi osayina mwalamulo (SCRIPT - zinthu zonse ndizofunikira):
U5.4.1. Wowukirayo amapanga kopi ya sitolo yachinsinsi.
U5.4.2. Owukirawo amasokoneza makiyi achinsinsi a m'modzi mwa otumiza ovomerezeka. Amawona kunyengerera, amachotsa makiyi, ndipo chidziwitso chokhudza kuchotsedwa kwachinsinsi chimayikidwa mu sitolo yachinsinsi.
U5.4.3. Zigawenga zilowa m'malo sitolo ya makiyi a anthu onse ndi yomwe inakopera kale.
U5.4.4. Zigawenga zimasaina data yabodza ndi kiyi ya siginecha yamagetsi yomwe idasokonezedwa kale ndikuyibaya munjira yotetezeka yosinthira deta.
U5.5. <β¦> chifukwa cha kukhalapo kwa zolakwika pakukhazikitsa gawo lachiwiri ndi lachitatu pakutsimikizira siginecha yamagetsi: Kufotokozera U5.5.
Chitsanzo cha kukhazikitsidwa kwa chiwopsezochi chaperekedwa pansipa.
U5.5.1. Kuyang'ana kukhulupilira pa satifiketi yamakiyi a siginecha yamagetsi pokhapokha ngati pali chidaliro pa satifiketi yomwe idasainidwa, popanda macheke a CRL kapena OCSP. Kufotokozera U5.5.1.
Chitsanzo chokhazikitsa zoopseza.
U5.5.2. Pomanga chain trust for satifiketi, olamulira opereka satifiketi samawunikidwa Kufotokozera U5.5.2.
Chitsanzo cha kuwukira kwa satifiketi za SSL/TLS.
Otsutsawo adagula satifiketi yovomerezeka ya imelo yawo. Kenako adapanga chiphaso chachinyengo cha malo ndikusaina ndi satifiketi yawo. Ngati zidziwitso siziyang'aniridwa, ndiye kuti poyang'ana mndandanda wa trust udzakhala wolondola, ndipo, motero, satifiketi yachinyengo idzakhalanso yolondola.
U5.5.4. Ma CRL amasinthidwa pafupipafupi kuposa momwe amaperekera certification.
U5.5.5. Lingaliro lokhulupirira siginecha yamagetsi limapangidwa asanayankhe OCSP za momwe satifiketiyo ilili, yotumizidwa pa pempho lomwe lapangidwa mochedwa kuposa nthawi yomwe siginecha idapangidwa kapena kale kuposa CRL yotsatira siginecha itapangidwa. Kufotokozera U5.5.5.
M'malamulo a ma CA ambiri, nthawi yochotsa satifiketi imatengedwa kuti ndi nthawi yotulutsidwa kwa CRL yapafupi yomwe ili ndi chidziwitso chokhudza kuchotsedwa kwa satifiketi.
U5.5.6. Mukalandira zidziwitso zosainidwa, satifiketiyo ndi ya wotumizayo samafufuzidwa. Kufotokozera U5.5.6.
Chitsanzo cha kuukira. Pokhudzana ndi ziphaso za SSL: kulemberana kwa adilesi yotchedwa seva ndi mtengo wa gawo la CN mu satifiketi sikungawunikidwe.
Chitsanzo cha kuukira. Zigawenga zasokoneza makiyi a siginecha apakompyuta a m'modzi mwa omwe adatenga nawo gawo pamakina olipira. Pambuyo pake, adalowa pa intaneti ya wina yemwe adatenga nawo gawo ndipo, m'malo mwake, adatumiza zikalata zolipirira zomwe zidasainidwa ndi makiyi osokonekera ku seva yolipira. Ngati seva imangosanthula kukhulupirirana ndipo sichiyang'ana kuti ikutsatiridwa, ndiye kuti zolemba zachinyengo zimaonedwa kuti ndizovomerezeka.
U6. Kuvomereza molakwika zikalata zamagetsi kuti aphedwe chifukwa cha zovuta pakukonza kasamalidwe ka zikalata zamagetsi.
U7. Kufikira kosaloledwa kwa data yotetezedwa panthawi yomwe akukonzedwa ndi CIPF
Kuwola
U7.1. <β¦> chifukwa cha kutayikira kwa chidziwitso kudzera pamakina am'mbali (kuukira kwa tchanelo chakumbali). Kufotokozera U7.1.
Chitsanzo: kuwukira.
U7.2. <β¦> chifukwa cha kusalowerera ndale kwa chitetezo kuzinthu zosaloledwa zomwe zakonzedwa pa CIPF:
U7.2.1. Kugwira ntchito kwa CIPF mophwanya zofunikira zomwe zafotokozedwa muzolemba za CIPF.
U7.2.2. <β¦>, zomwe zimachitika chifukwa cha kupezeka kwa ziwopsezo mu:
U7.2.2.1. <β¦> njira zodzitetezera kuti musapezeke mosaloledwa.
U7.2.2.2. <β¦> CIPF yokha.
U7.2.2.3. <...> malo ogwiritsira ntchito crypto-Tool.
Zitsanzo za kuukira
Zochitika zomwe zafotokozedwa m'munsimu mwachiwonekere zili ndi zolakwika zokhudzana ndi chitetezo ndipo zimangosonyeza ziwonetsero zomwe zingatheke.
Chitsanzo 1. Chitsanzo cha kukhazikitsidwa kwa ziwopsezo za U2.2 ndi U4.2.
Kufotokozera kwa chinthu
Mapulogalamu a AWS KBR ndi Siginecha ya CIPF SCAD amaikidwa pa kompyuta yomwe siinalumikizidwa ndi netiweki yamakompyuta. FKN vdToken imagwiritsidwa ntchito ngati chonyamulira chachikulu munjira yogwirira ntchito ndi kiyi yosachotsedwa.
Malamulo okhazikika amalingalira kuti katswiri wokhazikika pakompyuta yake amatsitsa mauthenga apakompyuta m'mawu omveka bwino (dongosolo la malo ogwirira ntchito a KBR) kuchokera pa seva yapadera yotetezedwa ya fayilo, kenako amawalemba pa USB flash drive yosunthika ndikuwasamutsira ku malo ogwirira ntchito a KBR, kumene iwo ali obisika ndi zizindikiro. Pambuyo pake, katswiriyo amasamutsa mauthenga otetezeka apakompyuta kwa otalikirana, ndiyeno, kupyolera mu kompyuta yake ya ntchito, amawalembera ku seva ya fayilo, kumene amapita ku UTA ndiyeno ku Bank of Russia.
Pankhaniyi, njira zosinthira deta yotseguka ndi yotetezedwa iphatikiza: seva yamafayilo, kompyuta yantchito ya akatswiri, ndi media zosiyanitsidwa.
Kuukira
Owukira osaloleka amayika makina owongolera akutali pakompyuta ya akatswiri ogwira ntchito ndipo, panthawi yolemba malamulo olipira (mauthenga amagetsi) kupita ku sing'anga yosamutsidwa, m'malo mwake zomwe zili m'modzi mwa iwo momveka bwino. Katswiriyo amasamutsa maoda olipira ku malo ogwirira ntchito a KBR, amasaina ndikuwalemba osazindikira kuti alowa m'malo (mwachitsanzo, chifukwa cha kuchuluka kwa zolipira paulendo wa pandege, kutopa, ndi zina). Pambuyo pake, dongosolo la malipiro abodza, litadutsa muzitsulo zamakono, likulowa mu dongosolo la malipiro a Bank of Russia.
Chitsanzo 2. Chitsanzo cha kukhazikitsidwa kwa ziwopsezo za U2.2 ndi U4.2.
Kufotokozera kwa chinthu
Kompyuta yokhala ndi malo ogwirira ntchito a KBR, Siginecha ya SCAD ndi chonyamulira makiyi olumikizidwa FKN vdToken imagwira ntchito m'chipinda chodzipatulira popanda anthu ogwira ntchito.
Katswiri wowerengera amalumikizana ndi malo ogwirira ntchito a CBD mumayendedwe akutali kudzera pa protocol ya RDP.
Kuukira
Zigawenga zimadumphadumpha mwatsatanetsatane, pogwiritsa ntchito zomwe katswiri wowerengerayo amalumikiza ndikugwira ntchito ndi malo ogwirira ntchito a CBD (mwachitsanzo, kudzera pa code yoyipa pakompyuta yake). Kenako amalumikiza m'malo mwake ndikutumiza chikalata chabodza ku Bank of Russia yolipira.
Chitsanzo 3. Chitsanzo cha kuwopseza kugwiritsa ntchito U1.3.
Kufotokozera kwa chinthu
Tiyeni tilingalire imodzi mwazinthu zongoyerekeza pakukhazikitsa ma module ophatikizira a ABS-KBR a chiwembu chatsopano (AWS KBR-N), pomwe siginecha yamagetsi yamakalata otuluka imapezeka kumbali ya ABS. Pankhaniyi, tiganiza kuti ABS imagwira ntchito pamaziko a makina ogwiritsira ntchito omwe samathandizidwa ndi CIPF SKAD Signature, ndipo, motero, ntchito ya cryptographic imasamutsidwa kumakina apadera - kuphatikiza kwa "ABS-KBR" moduli.
Chizindikiro cha USB chokhazikika chomwe chimagwira ntchito mumakina obwezerezedwanso chimagwiritsidwa ntchito ngati chonyamulira chachikulu. Pamene kulumikiza TV kiyi kwa hypervisor, kunapezeka kuti panalibe ufulu madoko USB mu dongosolo, choncho anaganiza kulumikiza chizindikiro USB kudzera maukonde USB likulu, ndi kukhazikitsa USB-pa-IP kasitomala pa pafupifupi. makina, omwe amalumikizana ndi likulu.
Kuukira
Owukirawo adalanda chinsinsi chachinsinsi cha siginecha yamagetsi kuchokera panjira yolumikizirana pakati pa USB hub ndi hypervisor (deta idatumizidwa momveka bwino). Pokhala ndi kiyi yachinsinsi, owukirawo adapanga chikalata chabodza, ndikuchisaina ndi siginecha yamagetsi ndikutumiza kumalo ogwirira ntchito a KBR-N kuti akaphedwe.
Chitsanzo 4. Chitsanzo cha kukhazikitsidwa kwa ziwopsezo U5.5.
Kufotokozera kwa chinthu
Tiyeni tilingalire dera lomwelo monga momwe zidalili kale. Tiganiza kuti mauthenga a pakompyuta ochokera ku malo ogwirira ntchito a KBR-N amathera pa ...SHAREIn foda, ndipo omwe amatumizidwa ku malo ogwirira ntchito a KBR-N komanso kumalipiro a Bank of Russia amapita ku ...SHAREout.
Tidzaganizanso kuti pokhazikitsa gawo lophatikizira, mindandanda ya ziphaso zochotsedwa imasinthidwa pokhapokha makiyi a cryptographic atulutsidwanso, komanso kuti mauthenga apakompyuta omwe alandilidwa muβ¦SHAREIn chikwatu amangoyang'aniridwa kuti athe kuwongolera umphumphu ndi kudalirika mu kiyi ya anthu onse. siginecha yamagetsi.
Kuukira
Owukirawo, pogwiritsa ntchito makiyi omwe adabedwa muzochitika zam'mbuyomu, adasaina chikalata chabodza chokhala ndi chidziwitso chokhudza kulandira ndalama muakaunti ya kasitomala wachinyengo ndikuzilowetsa munjira yotetezeka yosinthira deta. Popeza palibe chitsimikiziro chakuti lamulo lolipira lidasainidwa ndi Bank of Russia, likuvomerezedwa kuti liphedwe.