农业大数据学报 ›› 2024, Vol. 6 ›› Issue (2): 259-268.doi: 10.19788/j.issn.2096-6369.000051

• “面向高质量共享的科学数据安全”专刊(上) • 上一篇    下一篇

空间环境科学数据安全分级概念框架研究

许琦1,2(), 胡晓彦1,2,3,*(), 邹自明1,2, 佟继周1,2   

  1. 1.中国科学院国家空间科学中心,北京 100190
    2.国家空间科学数据中心,北京 100190
    3.中国科学院大学,北京 101408
  • 收稿日期:2024-05-15 接受日期:2024-06-12 出版日期:2024-06-26 发布日期:2024-07-03
  • 通讯作者: 胡晓彦,E-mail: huxiaoyan@nssc.ac.cn
  • 作者简介:许琦,E-mail: xuqi@nssc.ac.cn
  • 基金资助:
    空间科学大数据智能管理与分析挖掘关键技术及应用(2022YFF0711400);相关领域科技资源安全基础技术标准研究和示范验证(2019YFF0216205);空间环境领域科学数据安全分类分级规范研究(CAS-WX2023ZX01-0504)

Research on the Security Classification Conceptual Framework of Space Environment Scientific Data

XU Qi1,2(), HU XiaoYan1,2,3,*(), ZOU ZiMing1,2, TONG JiZhou1,2   

  1. 1. National Space Science Center, Chinese Academy of Sciences, Beijing 100190, China
    2. National Space Science Data Center, Beijing 100190, China
    3. University of Chinese Academy of Sciences,Beijing 101408, China
  • Received:2024-05-15 Accepted:2024-06-12 Published:2024-06-26 Online:2024-07-03

摘要:

建立多维度、全面覆盖空间环境数据资源特性的安全分级概念框架,形成领域数据安全分级规则,是落实国家数据安全法要求,开展细粒度的领域数据安全分级管理工作的必要前提。空间环境科学数据资源具有多来源、多类型、多时空分辨率、多模态等特点,国家空间科学数据中心为满足流通共享、学科应用与安全管理等多方面的需求,通过个案研究法、定性分析法对其他行业领域数据安全分级标准的级别划分方法与不同级别数据资源特征进行梳理分析。研究形成基于领域和数据资源特点组和后逆向分析数据遭到破坏后对不同影响对象的影响程度,并将影响程度映射到数据安全分级规则后确定安全级别的逻辑主线,构建了能够适用于各类空间环境科学数据的安全分级概念框架。空间环境科学数据安全分级概念框架提出了领域数据分类基础上识别数据特征识别的方法,给出了依据保密性、完整性、可获取性和真实性的安全影响评估的方法和数据安全分级规则参考框架,为空间环境领域数据安全分级管理的落地实施提供依据,为领域重要数据目录的形成提供支撑。

关键词: 数据安全, 数据分类分级, 空间环境科学数据安全分级

Abstract:

It is necessary that establish a multi-dimensional and comprehensive security classification framework for space environmental data resources and form domain data security classification rules for complying with the requirements of the Data Security Law of the People's Republic of China and carrying out fine-grained domain data safety grading management. Space environmental scientific data resources are characterized by multiple-sources, multiple types, multiple spatial and temporal resolutions, and multiple modes. In order to meet the needs of data flow and sharing, domain data application, security management and so on, the National Space Science Data Center(NSSDC)has combined and analyzed the classification methods and features of different levels of data resources for the data security classification standards in other industries through case study and qualitative analysis. A logical line for determining the security level following damage is established by mapping it to data security classification rules, based on domain and data resource characteristics as well as post-reverse analysis. Based on these findings, a conceptual framework for data safety classification is developed that can be applied to various types of space environmental scientific data. The conceptual framework of space environmental scientific data security classification proposes a methodology for identifying data features based on domain data classification, and provides an approach for assessing security impacts based on confidentiality, integrity, accessibility, and authenticity. It also presents a reference framework for data security classification rules, which serves as the foundation for implementing data security classification management in the field of space environment and supports the establishment of an important data catalog in this domain.

Key words: data security, the classification and categorization of data security, the security classification of space environment scientific data