Home > other >  Security technology principle and instant messaging system
Security technology principle and instant messaging system

Time:12-01

With the rapid development of Internet, network information security has become a potentially huge problem, severe safety accidents affect the normal operation of the enterprise, so need to multi-dimensional on system architecture design, three-dimensional guarantee information security,
Main server storage information security need to be solved, the mobile end use safety, communication between client and server security
the three aspects of1, the server information storage security: news record store involves the company confidential information, all the system first of all you need is to be able to support the deployment of privatisation, secondly each session of the message should be independent encryption storage, even if the server is breached, others also unable to crack the encrypted data,
2, mobile terminal information security: mobile office now more common, so the mobile end use safety also need to pay special attention to, move the files, pictures, news, organization structure, all the data related to information security encryption storage, even if the user mobile phone is lost or stolen, and others could pass file management tools directly to check the documents and data, in addition the system also should have data erased function, cell phone in the absence of network, support the need to enter a security code to enter the APP, mobile client does not save the password or local password hash, only local preservation login ticket, can control the login server ticket validity, through the management background can set up the client login second validation, in case you fail to verify the user name and password, again through the message authentication code validation, to ensure foolproof,
3, the network communication security: client and server network communication encryption, all the long Socket connection USES TLS, short connection using HTTPS, in line with international standards of TLS1.2 encryption for data transmission, the key length: 2048 - bit RSA public/private key and a 256 - bit AES symmetric key, mobile phone login the client and server communication, network does not transmit passwords or password hash,
  • Related