节点文献

一种改进的Clark-Wilson完整性策略模型

An Improvement of Clark-Wilson Integrity Model

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 罗琴; 王小明; 付争方;

【Author】 LUO Qin1,WANG Xiao-ming1,3,FU Zheng-fang1,2(1 College of Computer Science,Shaanxi Normal University,Xi′an 710062,China;2 Department of Physics and Computer Science,Ankang College,Ankang 725000,China;3 Institute of Intelligent Information Process & Information Security,Shaanxi Normal University,Xi′an 710062,China)

【机构】 陕西师范大学计算机科学学院; 陕西师范大学计算机科学学院 陕西西安710062; 陕西西安710062; 陕西师范大学智能信息处理与信息安全研究所; 安康学院物理与计算机科学系; 陕西安康725000;

【摘要】 Clark-Wilson完整性策模型在商业安全领域可以有效满足企业信息系统所追求的完整性安全需求。但是直接将用户和权限关联,给权限的管理带来不便;对权限不加以时间约束,会带来安全隐患;在用户同谋的情况下,模型还会失效。基于上述缺陷,在用户和权限之间引入角色的概念,用户可以在受约束的情况下激活自己拥有的角色从而获得相应的权限,使Clark-Wilson完整性策略模型更具有安全特性。

【Abstract】 In commerce security field,Clark-Wilson integrity model can meet integrity need of enterprise information system.But it associated user with permission directly,so it is very difficult to manage permissions;the permissions are not restricted by the time,which may bring safe problems;if the users collude together,the model will be invalidation.For the above limitations,Clark-Wilson integrity model will have more safety characteristic by importing the role between users and permissions when user can activate roles under some constraints.

【基金】 国家自然科学基金项目(10571112);陕西省自然科学基金项目(2006F27)
  • 【文献出处】 微电子学与计算机 ,Microelectronics & Computer , 编辑部邮箱 ,2007年07期
  • 【分类号】TP311.13
  • 【被引频次】2
  • 【下载频次】146
节点文献中: 

本文链接的文献网络图示:

本文的引文网络