节点文献

NHSecure访问控制机制的研究与实现

Research and Implementation of Access Control Mechanisms in NHSecure

【作者】 戴华;

【导师】 秦小麟;

【作者基本信息】 南京航空航天大学 , 计算机应用技术, 2006, 硕士

【摘要】 信息技术的迅速发展使数据库面临的安全问题更加复杂和多样,数据库作为信息系统重要数据的存储和处理核心,往往成为最吸引攻击者的目标。访问控制(Access Control)技术是数据库安全领域的一个重要研究方向,传统的访问控制技术已越来越不能满足现代数据库的安全需求。本文对数据库访问控制理论和实现方法进行研究,并在此基础上,设计和实现了NHSecure数据库管理系统的安全子系统。本文主要的工作和创新点如下:⑴在传统的自主访问控制机制研究基础上,提出了一种基于双授权链集合的访问控制模型(DACS),该模型具有常规授权管理和阻断授权管理功能,支持8种授权和收权操作,同时具备阻断授权机制和独立收权机制。⑵设计并实现了基于DACS模型的自主访问控制机制,详细给出了NHSecure系统中自主访问控制机制的结构设计、权限设计、授权管理语言设计、子系统数据字典结构设计以及授权管理策略和权限仲裁策略的设计与实现。⑶设计并实现了基于MLR模型的强制访问控制机制,详细给出了NHSecure系统中强制访问控制机制的敏感度密级标记设计、SQL操作语句扩充、强制访问控制策略设计、子系统结构设计、存储结构设计和特权用户设计。

【Abstract】 With the rapid development of information and technology, database faces more serious security situation. As the center of storage and process for the important data, databases often become the targets of attacks. Research of the access control has been an important part in the field of database security, but the traditional access control technologies could not satisfy the requirements of modern database security.In this paper, we focus on the theories and implementations of access control in database, and we design and implement a security sub-system of NHSecure DBMS. The main work and research are listed as follows:⑴On the basis of traditional DAC mechanism research, we propose a double-authorization chain sets based access control (DACS) model, which supports 8 kinds of authorization management funtions including normal authorization and denial authorization, and have denial authorization mechanism and non-cascade revoking mechanism.⑵According to the definition and policies of DACS model, we design and implement the discretionary access control mechanism of NHSecure DBMS. And, we describe its’implementation in detail, such as the design of module structre, access privileges, authorization language, security data dictionary, authorization manage- ment policies and authorization arbitration policies.⑶We design and implement the mandatory access control mechanism of NHSecure DBMS, which is based on MLR model. And we mainly discuss the design of security levels, SQL statement extension, mandatory access control policies, module structre, data storage structre and the privileges for specific users.

  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】60
节点文献中: