面向数据要素流通的商用密码安全保障体系研究
网络出版日期: 2026-05-27
版权
Research on commercial cryptography security assurance system for data element circulation
Online published: 2026-05-27
Copyright
随着可信数据空间发展行动计划的出台,推动数据要素交易与流通已上升为国家战略。密码技术作为网络安全的核心技术与基础支撑,具备的机密性、完整性、真实性与不可否认性特征,为可信数据空间的数据安全提供了有力支撑。基于此,本文聚焦数据要素流通场景,从技术赋能、标准衔接、管理协同3个维度构建商用密码安全保障体系;通过梳理数据全生命周期安全应用需求,提出分层解耦的密码应用架构,搭建覆盖基础通用到应用测评的标准体系,建立兼具制度规范、监督评价与政策协同的综合管理机制。经与传统数据安全及密码应用体系对比分析,该体系在数据业务与密码功能融合深度、全链路安全防护、标准管理协同层面具备显著优势,能够为数据要素安全高效流通提供理论参考与实践路径。
黄晶晶 , 田涵宇 , 刘昕宇 , 蔡一鸣 , 周睿康 , 李琳 , 朱峰 . 面向数据要素流通的商用密码安全保障体系研究[J]. 网络空间安全科学学报, 2026 , 4(3) : 2 -12 . DOI: 10.20172/j.issn.2097-3136.260528
With the introduction of the action plan for the development of trusted data space, advancing the transaction and circulation of data elements has become a national strategy. As the core technology and fundamental support of network security, cryptographic technology possesses the characteristics of confidentiality, integrity, authenticity and non-repudiation, which strongly supports data security in trusted data space. Focusing on the scenario of data element circulation, this paper constructs a commercial cryptography security assurance system from three dimensions of technology empowerment, standard alignment and management synergy. By sorting out the security application requirements in the whole life cycle of data, this paper proposes a layered and decoupled cryptographic application framework, establishes a standard system covering general basic specifications to application evaluation, and builds a comprehensive management mechanism integrating institutional norms, supervision and evaluation, as well as policy coordination. Comparative analysis with traditional data security and cryptographic application systems shows that the proposed system has significant advantages in the integration depth of data business and cryptographic functions, full-link security protection, and the coordination of standards and management, which provides a theoretical reference and practical path for the secure and efficient circulation of data elements.
表 1 3种体系对比Table 1 Comparison of three systems |
| 对比内容 | 传统商用密码应用体系 | 传统数据安全通用体系 | 数据要素流通的商用密码安全保障体系 |
| 覆盖范围 | 侧重数据存储/传输的安全与 基础密码部署 | 侧重网络边界防护 与静态存储 | 侧重数据全生命周期防护 和跨域流通全链路 |
| 业务与密码融合度 | 以密码为中心,业务适配性弱 | 泛化适配,无行业差异 | 业务流内嵌密码功能,按需动态调用 |
| 标准协同 | 遵循密码国标,缺少 场景适配 | 数据标准和密码标准割裂 | 构建“基础—设施—技术—应用—测评”体系,实现数据流通 与密码应用的双向衔接 |
| 管理闭环 | 侧重技术实施,管理 机制偏弱 | 事后审计为主,缺乏密码 专项监督 | 组织—制度—监督—政策联动,保障数据要素流通过程中 密码应用持续合规、有效 |
| 可落地性 | 高,但有安全断点 | 中,缺少统一标准 | 高,标准配套、管理闭环 |
| 1 |
李凤华, 李晖, 牛犇, 等. 数据要素流通与安全的研究范畴与未来发展趋势[J]. 通信学报, 2024, 45 (5): 1- 11.
Li F H, Li H, Niu B, et al. Research category and future development trend of data elements circulation and security[J]. Journal on Communications, 2024, 45 (5): 1- 11.
|
| 2 |
杨明, 冯宏霖, 王鑫, 等. 数据要素市场研究综述: 价值、定价与交易[J]. 网络与信息安全学报, 2024, 10 (3): 1- 19.
Yang M, Feng H L, Wang X, et al. Survey of data factor market: value, pricing, and trading[J]. Journal of Network and Information Security, 2024, 10 (3): 1- 19.
|
| 3 |
中华人民共和国中央人民政府网. 中共中央关于制定国民经济和社会发展第十五个五年规划的建议 [EB/OL]. (2025-10-28)[2026-05-02] https://www.gov.cn/zhengce/202510/content_7046050.htm.
The Central People's Government of the People's Republic of China. Recommendations of the central committee of the communist party of China for formulating the 15th five-year plan for national economic and social development[EB/OL]. (2025-10-28)[2026-05-02] https://www.gov.cn/zhengce/202510/content_7046050.htm.
|
| 4 |
中华人民共和国国家发展和改革委员会网站. 国家发展改革委等部门印发《关于完善数据流通安全治理 更好促进数据要素市场化价值化的实施方案》的通知[EB/OL]. (2025-01-06)[2026-05-02] https://zfxxgk.ndrc.gov.cn/web/iteminfo.jsp?id=20473.
National Development and Reform Commission of the Peopl’s Republic of China. Notice of the National Development and Reform Commission and other departments on issuing the “implementation plan for improving data circulation security governance to better promote marketization and value realization of data elements” [EB/OL]. (2025-01-06) [2026-05-02] https://zfxxgk.ndrc.gov.cn/web/iteminfo.jsp?id=20473.
|
| 5 |
刘立伟, 傅超豪, 孙泽堃, 等. 数据要素流通全流程隐私关键技术: 现状、挑战与展望[J]. 软件学报, 2026, 37 (1): 301- 325.
Liu L W, Fu C H, Sun Z K, et al. Privacy key technologies in whole stages of data circulation: current situation, challenges, and prospects[J]. Journal of Software, 2026, 37 (1): 301- 325.
|
| 6 |
霍炜, 郁昱, 杨糠, 等. 隐私保护计算密码技术研究进展与应用[J]. 中国科学:信息科学, 2023, 53 (9): 1688- 1733.
Huo W, Yu Y, Yang K, et al. Privacy-preserving cryptographic algorithms and protocols: a survey on designs and applications[J]. Scientia Sinica Informationis, 2023, 53 (9): 1688- 1733.
|
| 7 |
霍炜, 郭启全, 马原. 商用密码应用与安全性评估[M]. 北京: 电子工业出版社, 2020: 2-3.
Huo W, Guo Q Q, Ma Y. Application and security evaluation of commercial cryptography[M]. Beijing: Publishing House of Electronics Industry, 2020: 2-3.
|
| 8 |
范建, 胡兴元, 刘京, 等. 可信数据空间安全防护体系研究[J]. 中国信息界, 2025 (8): 109- 111.
Fan J, Hu X Y, Liu J, et al. Research on security protection system of trusted data space[J]. Information China, 2025 (8): 109- 111.
|
| 9 |
王森, 许涛, 李金贵. 基于属性加密的数据共享管理研究[J]. 信息安全研究, 2023, 9 (11): 1061- 1066.
Wang S, Xu T, Li J G. Research on data sharing management based on attribute-based encryption[J]. Journal of Information Security Research, 2023, 9 (11): 1061- 1066.
|
| 10 |
尤玮婧. 数据要素确权中的密码学技术[J]. 中国计算机学会通讯, 2025, 21 (4): 35- 41.
You W J. Cryptographic technologies in data element right confirmation[J]. Communications of the CCF, 2025, 21 (4): 35- 41.
|
| 11 |
严星宇, 赵川, 徐雁飞. 券商行业商用密码应用与实践[J]. 信息安全研究, 2023, 9 (7): 707- 712.
Yan X Y, Zhao C, Xu Y F. Application and implementation of commercial cryptographic algorithm in securities industry[J]. Journal of Information Security Research, 2023, 9 (7): 707- 712.
|
| 12 |
王中武. 商用密码在数据仓库中的应用研究[J]. 信息安全与通信保密, 2025 (2): 97- 104.
Wang Z W. Research on the application of commercial cryptography in data warehouse[J]. Information Security and Communications Privacy, 2025 (2): 97- 104.
|
| 13 |
Suliman M, Halimi A, Kadhe S R, et al. Towards a re-evaluation of data forging attacks in practice[C]//34th USENIX Security Symposium (USENIX Security 25). Seattle: USENIX Association, 2025: 5505-5524.
|
| 14 |
Hu J M, Yang X F, Yang L X. A framework for detecting false data injection attacks in large-scale wireless sensor networks[J]. Sensors, 2024, 24 (5): 1643.
|
| 15 |
Rao Z Y, You L, Hu G R, et al. EBDTS: an efficient BCoT-based data trading system using PUF for authentication[J]. IEEE Transactions on Network and Service Management, 2024, 21 (5): 5795- 5808.
|
| 16 |
Chen F M, Zhao B, Gao Y L, et al. BTDA: Two-factor dynamic identity authentication scheme for data trading based on alliance chain[J]. The Journal of Supercomputing, 2023, 79 (17): 19118- 19137.
|
| 17 |
全国数据标准化技术委员会. 可信数据空间技术架构: TC609-6-2025-01[S], 北京: 全国数据标准化技术委员会, 2025.
National Technical Committee 609 on Data of Standardization Administration of China. Technical architecture of trusted data space: TC609-6-2025-01[S]. Beijing: National Technical Committee 609 on Data of Standardization Administration of China, 2025.
|
| 18 |
全国数据标准化技术委员会. 可信数据空间使用控制技术要求: TC609-6-2025-15[S]. 北京: 全国数据标准化技术委员会, 2025.
National Technical Committee 609 on Data of Standardization Administration of China. Technical requirements for usage control of trusted data space: TC609-6-2025-15[S]. Beijing: National Technical Committee 609 on Data of Standardization Administration of China, 2025.
|
| 19 |
田敏求, 夏鲁宁, 张众, 等. 我国密码行业标准综述(上)[J]. 信息技术与标准化, 2019 (3): 52- 55.
Tian M Q, Xia L N, Zhang Z, et al. Review on Chinese cryptography industry standards(part one)[J]. Information Technology & Standardization, 2019 (3): 52- 55.
|
| 20 |
田敏求, 夏鲁宁, 张众, 等. 我国密码行业标准综述(下)[J]. 信息技术与标准化, 2019 (4): 43- 48.
Tian M Q, Xia L N, Zhang Z, et al. Review on Chinese cryptography industry standards (part two)[J]. Information Technology & Standardization, 2019 (4): 43- 48.
|
| 21 |
吴龙, 杨洋. 商用密码在医院电子病历系统存储加密中的应用[J]. 中国卫生信息管理杂志, 2023, 20 (5): 715- 722,729.
Wu L, Yang Y. Application of domestic commercial password in storage and encryption reform of hospital electronic medical record system[J]. Chinese Journal of Health Informatics and Management, 2023, 20 (5): 715- 722,729.
|
| 22 |
白荣华, 魏强, 郭瑞, 等. 政务信息系统商用密码集约化平台设计与实现[J]. 信息安全研究, 2023, 9 (5): 461- 468.
Bai R H, Wei Q, Guo R, et al. Design and implementation of cryptography intensive platform for government information system[J]. Journal of Information Security Research, 2023, 9 (5): 461- 468.
|
| 23 |
姚红云, 褚瑞, 李红霞, 等. 基于国产商用密码的核安保系统解决方案研究[J]. 自动化仪表, 2023, 44 (S1): 268- 271,276.
Yao H Y, Chu R, Li H X, et al. Research on nuclear security system solutions based on domestic commercial passwords[J]. Process Automation Instrumentation, 2023, 44 (S1): 268- 271,276.
|
| 24 |
国家密码管理局网站. 关键信息基础设施商用密码使用管理规定[EB/OL]. (2025-06-27) [2026-04-10]. https://oscca. gov. cn/sca/xxgk/2025-06/27/content_1061270. shtml.
State Cryptography Administration of China. Provisions on administration of the use of commercial cryptography in critical information infrastructure[EB/OL]. (2025-06-27)[2026-04-10]. https://oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml.
|
| 25 |
IEEE standard for trusted data matrix system architecture[EB/OL]. (2024-12-13)[2026-04-10]. https://ieeexplore. ieee.org/document /10797717.
|
| 26 |
杨云龙, 张亮, 杨旭蕾. 可信数据空间助力数据要素高效流通[J]. 邮电设计技术, 2024 (2): 57- 61.
Yang Y L, Zhang L, Yang X L. Trusted data space helps efficient circulation of data elements[J]. Designing Techniques of Posts and Telecommunications, 2024 (2): 57- 61.
|
| 27 |
国家数据局. 国家数据局关于印发《可信数据空间发展行动计划(2024-2028 年)》的通知[EB/OL]. (2024-11-21)[2026-04-10]. https://www.gov.cn/zhengce/zhengceku/202411/content_6996363.htm.
National Data Administration. Notice of the national data administration on issuing the trusted data space development action plan (2024–2028)[EB/OL]. (2024-11-21)[2026-04-10]. https://www.gov.cn/zhengce/zhengceku/202411/content_6996363.htm.
|
| 28 |
刘振亚, 林璟锵. SM2数字签名算法的两方门限计算方案框架[J]. 软件学报, 2025, 36 (5): 2188- 2211.
Liu Z Y, Lin J Q. Framework of two-party threshold schemes for SM2 digital signature algorithms[J]. Journal of Software, 2025, 36 (5): 2188- 2211.
|
| 29 |
Thilakavathy P, Jayachitra S, Aeron A, et al. Investigating blockchain security mechanisms for tamper-proof data storage[C]//Proceedings of the 2023 International Conference on Communication, Security and Artificial Intelligence (ICCSAI). Piscataway: IEEE Press, 2023: 926-930.
|
| 30 |
Mohassel P, Zhang Y P. SecureML: a system for scalable privacy-preserving machine learning[C]//Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP). Piscataway: IEEE Press, 2017: 19-38.
|
| 31 |
Zhou I, Tofigh F, Piccardi M, et al. Secure multi-party computation for machine learning: a survey[J]. IEEE Access, 2024, 12, 53881- 53899.
|
| 32 |
房梁, 殷丽华, 郭云川, 等. 基于属性的访问控制关键技术研究综述[J]. 计算机学报, 2017, 40 (7): 1680- 1698.
Fang L, Yin L H, Guo Y C, et al. A survey of key technologies in attribute-based access control scheme[J]. Chinese Journal of Computers, 2017, 40 (7): 1680- 1698.
|
| 33 |
Steffen S, Bichsel B, Gersbach M, et al. Zkay: specifying and enforcing data privacy in smart contracts[C]//Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2019: 1759-1776.
|
| 34 |
Yang X Y, Luo Q C, Xu J, et al. Data secure storage mechanism for trustworthy data space[J]. Electronics, 2025, 14 (21): 4348.
|
| 35 |
Gentry C. Fully homomorphic encryption using ideal lattices[C]//Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing. New York: ACM, 2009: 169-178.
|
| 36 |
黄晶晶, 孙淑娴, 周睿康, 等. 商用密码应用安全性评估[J]. 信息安全与通信保密, 2023 (3): 113- 121.
Huang J J, Sun S X, Zhou R K, et al. Security evaluation of commercial cryptography application[J]. Information Security and Communications Privacy, 2023 (3): 113- 121.
|
/
| 〈 |
|
〉 |