内网环境下的安全与合规留痕
Ant Messenger 内网版面向政企提供隔离环境下的安全机制 that adopts the international mainstream end-to-end encryption method to secure messages, and supports instant burn after reading, anti-screenshot, and two-way deletion without leaving traces.
本页汇总 Ant Messenger 内网版在隔离环境中的传输加密、分级管控、操作留痕与日志导出机制。
安全机制一览
以下机制均来自 pro-antmessenger.com.cn 的公开说明。
| 消息加密 | 端到端加密 using the international mainstream method. |
|---|---|
| 阅后即焚消息 | Supports 阅后即焚. |
| 截屏控制 | 防截屏 protection. |
| 消息删除 | 双向删除 without leaving traces. |
| 群消息传输 | Group messages are encrypted through TLS, in groups of up to 10 万 people. |
| 云盘存储 | Files uploaded to the cloud disk are 高强度加密, with no limit on capacity or time. |
| 身份隐私 | Phone number and user ID can be 可隐藏; an 应用锁 can be set. |
| 设备接入 | Up to 5 台设备 can be logged in simultaneously with real-time chat sync. |
| 源码可用性 | 开源 — the source code can be viewed free of charge. |
Ant Messenger 如何保护消息安全
Ant Messenger 内网版在完全离线的环境中运行,消息加密传输与存储,并支持全量操作留痕与日志导出。
Because the application is 开源, the implementation can be inspected directly. Ant Messenger states that users are free to use and view the source code.
阅后即焚与双向删除
Ant Messenger supports 阅后即焚, so a message can be made to disappear once it has been read. It also supports 双向删除不留痕, which removes the message for both sides of the conversation rather than only on the device that issued the deletion.
防截屏保护
In addition to ephemeral and deletable messages, Ant Messenger provides 防截屏 protection. This is intended to limit copying of conversation content through device screenshots.
群组与云盘安全
Ant Messenger supports 超级群组 with up to 10 万人 communicating online. Group messages are encrypted through TLS (Transport Layer Security), which protects group traffic while it travels over the network.
For files, Ant Messenger provides 云盘存储. Files uploaded to the cloud disk are described as highly encrypted, and there is 不限容量、不限时间.
账号与设备保护
隐藏身份标识
你可以隐藏手机号与用户 ID,减少在其他参与者面前暴露的个人信息。
应用锁
可为应用设置应用锁,限制他人在本设备上查看你的会话。
多设备管理
最多 5 台设备可同时登录并实时同步,你可以随时查看账号在哪些设备上处于活跃状态。
关于内网安全与合规的常见问题
内网不连公网也能部署吗?
可以。服务端与客户端均支持离线安装,不依赖公网即可完成全员通讯。
是否支持国产系统?
支持。适配麒麟、统信 UOS 等国产操作系统与国产数据库。
能否满足等保要求?
支持配置口令策略、登录审计与数据留存,并提供全量操作日志导出。
账号能否统一登录?
支持 LDAP/AD 账号统一登录与分级管理员配置。
审计日志能导出吗?
可以。操作留痕与登录审计日志均支持导出与留存。