透過您的圖書館登入
IP:3.133.86.172
  • 期刊
  • OpenAccess

設計具資料保密暨動態存取之安全機制-以空軍管理資訊系統為例

Design Secure Mechanisms with Data Confidentiality and Dynamic Access-A Case Study for Air Force Management Information System

摘要


我國個人資料保護法已於2012年10月1日正式實施,資料保密儼然已成為基本且重要的問題。然而近年來,軍方內部重要資科外洩情形不斷發生,空軍管理資訊系統儲存了龐大的個人資料,若沒有採取適當資料保密安全機制,極易成為竊取的目標,並造成洩密事件發生。根據美國電腦安全協會的調查數據顯示,公司機密資料外洩的狀況有70%是由內部合法使用者所造成,因此,資料保密儼然已成為基本且重要的問題。如何加強空軍管理資訊系統資科存放安全與使用人員身分認證與管控,為本研究之目的。本研究針對資料庫資料保護情形及保護措施,以橢圓曲線密碼系統加密演算法,作為控管機敏資訊隱藏設計參考,提出整合資料庫身分認證、欄位加密與存取控制方法,以達到資料庫安全控管,並符合個人資料保護法各項法令規章。

並列摘要


The law of personal information protection has become effective since October 1^(st) 2012 in our country; in the meanwhile, data confidential has become an essential and important issue. In recent years, however, important information divulgence within the military continues to occur. Due to the massive personal information has been storing in Air Force management information system, it’s easyto become target if we don’t take appropriate confidentiality security measures for information, and leaking events would occurred. According to America computer security associationreports, there are 70% of company classified documents leakage events caused by internal legal users. Thus, the data confidential has become an essential and important issue. The purpose of this study is how to strengthen the Air Force Management Information System data storage security and identity authentication and the use of personnel control. In this study, we focused on database protection situation and protection measures, using Elliptic Curves Cryptography as the reference of controlling classified information conceal design, advancing measures of integrated database ID identification, column encryption and access control. With the proposed securemechanism, we could accomplish database security control and meet the government degrees of personal information protection law.

延伸閱讀