The invention relates to the technical field of
information security defense, in particular to a defense
system for
information security of a trusted
data space. The
system comprises a data
encryption module, an environment
verification module, a response execution module, a data use monitoring module and a block chain evidence storage module. According to the data sensitivity and the real-time
network delay, the bit number of the security key is dynamically selected, the attribute-based
encryption or proxy re-
encryption technology is adopted, the data and the
executable strategy are packaged into the trusted data unit, when the data reach the
edge node, the credibility of the node environment is strictly verified through
integrity measurement and remote certification, and the reliability of the node environment is improved. And after the
verification is passed, dynamic
authorization is performed in combination with a real-time context, the data is decrypted for use, whether to increase or decrease the security key bit is intelligently decided based on the violation frequency and the
performance index so as to seek the optimal balance between the security and the performance, and low time
delay and
high availability can be maintained while the integrity and
confidentiality of the data are guaranteed on the whole.