To overcome the limitations of perimeter-based security models in responding to internal security threats, a Zero Trust security model was proposed, along with various security technologies and concepts such as SDP to support it. However, in container platforms, network access control functions operate on the host system, which presents a limitation in that it is difficult to implement SDP for multiple information services on a single platform. Accordingly, this study proposes an SDP architecture to implement a Zero Trust security model in a container service environment. The proposed architecture consists of a container agent within the information service that sets user access control policies, a Side-Car container that verifies users, and a host agent that applies access control policies. Structurally, SDP can be implemented by a host agent that operates via a polling method. However, since this study focused on the SDP architecture for container environments, further research on SPA protocols for SDP is necessary.
한국어
경계 기반 보안 모델의 내부 보안 위협 대응이 어려운 한계점을 극복하기 위해 제로 트러스트 보안 모델이 제안되었으며,이를 뒷받침하기 위한 다양한 보안 기술이나 SDP 등의 개념이 제안되었다. 그러나 컨테이너 플랫폼에서는 네트워크 접근통제 기능이 호스트 시스템에서 동작하여 하나의 플랫폼에서 다수의 정보서비스를 위한 SDP 구현이 어려운 한계가 있다. 이에 따라 본 연구에서는 컨테이너 서비스 환경에 대하여 제로 트러스트 보안 모델을 구현하기 위한 SDP 아키텍처를 제안한다. 제안하는 아키텍처는 사용자 접근통제 정책을 설정하는 정보 서비스 내부의 컨테이너 에이전트와 사용자를 검증하는 Side-Car 컨테이너, 접근통제 정책을 적용하는 호스트 에이전트로 구성된다. 구조적으로 폴링 방식으로 동작하는 호스트 에이전트에 의해 SDP를 구현할 수 있다. 다만 본 연구는 컨테이너 환경에 대한 SDP 아키텍처에 집중하였으므로, SDP를 위한 SPA 프로토콜에 대한 추가 연구가 필요하다.
목차
요약 ABSTRACT 1. 서론 2. 관련 연구 2.1 제로 트러스트와 SDP 관계 2.2 컨테이너 플랫폼 2.3 SDP 구현을 위한 컨테이너 기반 정보 서비스보안 환경 분석 3. 컨테이너 환경을 위한 SDP 아키텍처 3.1 컨테이너 플랫폼 기반 정보 서비스를 위한 제로 트러스트 SDP 아키텍처 3.2 SDP 아키텍처의 동작 절차 4. 아키텍처 검증 4.1 검증 환경 및 검증 방법 4.2 검증 항목 및 검증 결과 5. 결론 참고문헌