节点文献

基于格的BLP完整性扩展模型

BLP Integrity Expansion Model on Lattice

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 沈瑛沈昌祥

【Author】 SHEN Ying1,2,SHEN Chang-xiang1,3(1.College of Computer Science and Technology,Zhejiang University,Hangzhou 310027,China; 2.College of Computer Science and Technology,Zhejiang University of Technology,Hangzhou 310023,China; 3.College of Computer Science,Beijing University of Technology,Beijing 100124,China)

【机构】 浙江大学计算机学院浙江工业大学计算机学院北京工业大学计算机学院

【摘要】 为了扩展BLP模型融入完整性,并解决BLP与Biba模型典型融合中的高保密完整性资源与低保密完整性资源互访困难问题,从数学背景乘积格角度分析BLP模型,构造了BLP-I扩展模型.BLP-I模型中标签的第2维分量改为可信级别,通过突出保密性中读操作和完整性中写操作的地位,区分主体和已读信息的可信级,协调了在生命周期内BLP模型的静态特性和Biba模型的动态特性.BLP-I模型以低保密完整性下级可向高保密完整性上级直接汇报,而上级主体可下调自身安全级间接向下级发指令的方式部分解决了互访困难问题.

【Abstract】 Mutual access dilemma between double-high level and double-low level resources in security and integrity was usually appeared during BLP model expansion with Biba.BLP model expansion with integrity which could resolve this dilemma was represented.An expansion model named BLP-I model was constructed in the view of product lattice analysis since lattice was BLP’s mathematical background.The second dimension of label in BLP-I was substituted to indicate trust level.Read operation in security attribute and write operation in integrity were highlighted.The trust level of subject and messages had been read were distinguished.So the tranquility in BLP and dynamics in Biba during a lifecycle were coordinated in BLP-I.At last,dilemma was partially solved in BLP-I by permitting low security and integrity level direct report to double-high level while permitting double-high level lowered its own security level to issue to its underling.

【关键词】 访问控制信息系统安全系统
【Key words】 access controlinformation systemssecurity systems
【基金】 国家科技重大专项基金资助项目(2010ZX01037-001-001);国家软科学研究计划资助项目(2010GXQ5D317);浙江省重点科技创新团队基金资助项目(2009R50009)
  • 【文献出处】 北京工业大学学报 ,Journal of Beijing University of Technology , 编辑部邮箱 ,2013年03期
  • 【分类号】TP309
  • 【被引频次】6
  • 【下载频次】121
节点文献中: 

本文链接的文献网络图示:

本文的引文网络