节点文献

基于WinCE操作系统安全技术的研究与实现

【作者】 陈志平

【导师】 雷航;

【作者基本信息】 电子科技大学 , 计算机应用, 2006, 硕士

【摘要】 随着计算机功能的日益强大,成本减少,特别是由于硬件体积大大缩小、功耗降低,计算机软件的快速发展和计算机网络的全面普及,大量可接入互联网的电子产品以嵌入式系统的方式普及到人们生活的各个方面。嵌入式系统的安全性问题变得越来越重要。操作系统作为嵌入式系统中核心部件,如果没有健全的安全保障机制,那构建在其上的应用系统及整个嵌入式系统的安全性将的不到根本的保证。嵌入式操作系统的安全性研究处于起步阶段,还没有成熟的技术。本文在研究分析传统安全操作系统的安全理论和技术的基础上,结合嵌入式操作系统的特点,提出了一种适合于嵌入式操作系统的安全核框架:ESK_EC (embedded security kernel of Win CE)。该安全核具有以下创新:1.依据应用场合不同,允许系统管理员进行安全策略配制,即设置不同的安全级别,以及对不同安全级别赋予不同的安全权限。2.提出了支持MLS、RBAC、DTE的多策略模型,并设计了多策略集成语言。3.为保证高安全性,安全核中采用强制访问控制技术,使得对内核的每个接口调用都能够进行安全检测。4.为实现以上技术,采用了安全标记技术,安全标记号映射为安全权限。5.在安全核中,为了加快决策速度,采用了决策缓存技术。使得整个安全核的效率提高。基于以上理论,在嵌入式操作系统Win CE4.2操作系统中实现了安全核原型,并通过验证测试,表明该安全核的功能和性能满足嵌入式系统的要求。本论文中对嵌入式操作系统安全技术的研究和实验,对嵌入式安全操作系统的研究起了一个铺垫作用,对进一步的研究具有一定的参考价值。

【Abstract】 Along with computer functions more powerful, cost reducing, especially because of hardware cubage reducing greatly, power cost falling, software developing fast and networks prevelence, many electronic productions which can be linked to internet gains ground every aspects of people’s life in embedded sysytem modes. The security problems of embedded system become more and more important. Operating system is the core part of the embedded system. If it is not protected well, the security of the application system and the whole embedded system built on it can not be protected thoroughly. Research on security of embedded operating system is on the beginning step, and there are not ripe technologies.This paper, after researching and analysing the security theories and technologies of traditional security operating system, with the characteristics of the embedded system, puts forward a security kernel frame which is suitable for embedded operating system: ESK_EC(embedded security kernel of Win CE). The security kernel has the innovations as below:1. Base on different applications, the system administrator can put up the security policy. He can set up different security levels, and put different security purviews to different security levels.2. This paper puts forward multi-policy model which holds out MLS, DTE and RBAC, and designs the multi-policy integration language.3. In order to ensure high security, this paper adopts MAC technology. Each use of the interfaces will be checked.4. This paper adopts security marker technology. Security marker is mapped to security purviews.5. In the security kernel, in order to pick up the speed of decision-making, this paper adopts decision-making buffer techonlogy. The efficiency of the security kernel is advanced.Base on the theories upwards, this paper realizes the security kernel prototype in the Win CE4.2 operating system. After test, it is indicated that the functions and the

  • 【分类号】TP316;TP309
  • 【被引频次】2
  • 【下载频次】280
节点文献中: 

本文链接的文献网络图示:

本文的引文网络