首页 | 本学科首页   官方微博 | 高级检索  
     

基于Web操作系统的移动瘦终端多安全策略模型
引用本文:杨莹,夏剑锋,朱大立.基于Web操作系统的移动瘦终端多安全策略模型[J].计算机科学,2018,45(11):108-114.
作者姓名:杨莹  夏剑锋  朱大立
作者单位:中国科学院大学网络空间安全学院 北京100093;中国科学院信息工程研究所 北京100093,中国科学院大学网络空间安全学院 北京100093;中国科学院信息工程研究所 北京100093,中国科学院信息工程研究所 北京100093
基金项目:本文受中国科学院战略性先导专项项目(XDA06010703)资助
摘    要:高安全级移动办公对信息系统不断提出更高的安全需求,在此背景下出现了瘦终端(Thin-Client)解决方案。其采用云存储、分布式终端系统和集中管理,为用户提供了更好的安全性。当前的主要技术包括虚拟桌面和Web终端,其中前者是主流。近年来,Web操作系统(Web OS)的发展促使Web终端受到业界重视,但Web OS还存在机密性和完整性保护不足的问题。基于Web OS系统的特点抽象建模,提出了混合机密性模型BLP和完整性模型Biba的多安全策略模型。首先利用格将机密性标签、完整性标签和范畴集合相结合,解决了BLP与Biba信息流相反的问题;然后提出可信主体的最小特权原则来进一步约束可信主体的权限,并给予特定可信主体临时权限,以提高灵活性和可用性;最后分析模型的安全性和适用性。

关 键 词:移动瘦终端  Web操作系统  安全模型    访问控制
收稿时间:2017/10/22 0:00:00
修稿时间:2018/1/24 0:00:00

Multi-policy Security Model of Mobile Thin Client Based on Web Operating System
YANG Ying,XIA Jian-feng and ZHU Da-li.Multi-policy Security Model of Mobile Thin Client Based on Web Operating System[J].Computer Science,2018,45(11):108-114.
Authors:YANG Ying  XIA Jian-feng and ZHU Da-li
Affiliation:School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100093,China;Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China,School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100093,China;Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China and Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China
Abstract:High-security mobile office has put forward growing security requirements on information systems.In this context,thin-client based solution exists.The solution takes the advantages of cloud storage,distributed terminal system and centralized management,and provides better safeguard for users.Nowadays,the main technologies of thin client are virtual desktop infrastructure (VDI) and Web-client,in which the former is the mainstream,while the latter has received widespread attention with the development of Web-based operating system (Web OS).However,there are some problems,including lower confidentiality and integrity in the existing Web OSes.Based on the abstract modeling of Web OS,this paper proposed a hybrid model by mixing BLP model and Biba model.In order to solve the collision of information flow,a lattice structure was introduced.Since information flow model has no constraints on trusted subjects,the principle of least privilege on trusted subject was promoted.To improve the flexibility and availability,a special trusted subject was authorized to change the security level temporarily.Finally,the security and applicability were analyzed.
Keywords:Mobile thin client  Web OS  Security model  Lattice  Access control
点击此处可从《计算机科学》浏览原始摘要信息
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号