节点文献
基于访问控制空间的多策略安全体系结构
Security Architecture to Support Multiple Security Policies Based on Access Control Space
【Author】 Li Li-Ping, Qing Si-Han, He Ye-Ping Institute of Software, The Chinese Academy of Sciences, Beijing 100080, China
【机构】 中国科学院软件研究所;
【摘要】 为解决LSM在策略重用和策略共存方面存在的问题,提出一个新的安全体系结构ELSM,引入模型组合器作为主模块实施模块堆栈管理和模块决策管理,后者基于访问控制空间的策略规范方法以实现通用性。本文介绍了ELSM的设计实现并给出了安胜OS安全操作系统中的实例。
【Abstract】 To solve the problems of policy reusability and policy co-existence, a new security architecture ELSM is proposed. It introduced Model Combiner as main module to implement module stack management and module decision management. Module decision is based on access control space as policy specification for general support. This paper illustrated the design of ELSM and gave the ERCIST OS implementation as an example.
【Key words】 security architecture; security policy model; Linux Security Module(LSM); policy specification;
- 【会议录名称】 全国网络与信息安全技术研讨会’2005论文集(下册)
- 【会议名称】全国网络与信息安全技术研讨会’2005
- 【会议时间】2005-08
- 【会议地点】中国北京
- 【分类号】TP393.08
- 【主办单位】信息产业部互联网应急处理协调办公室