首页 | 本学科首页   官方微博 | 高级检索  
     

一个安全标记公共框架的设计与实现
引用本文:梁洪亮,孙玉芳,赵庆松,张相锋,孙波.一个安全标记公共框架的设计与实现[J].软件学报,2003,14(3):547-552.
作者姓名:梁洪亮  孙玉芳  赵庆松  张相锋  孙波
作者单位:中国科学院软件研究所,北京,100080
基金项目:Supported by the National Natural Science Foundation of China under Grant No.60073022 (国家自然科学基金); the National High Technology Development 863 Program of China under Grant No.863-306-ZD12-14-2 (国家863高科技发展计划); the Knowledge Innovation Engineering Program of the Chinese Academy of Sciences under Grant No.KGCX1-09 (中国科学院知识创新工程)
摘    要:标记是实现多级安全系统的基础,实施强制访问控制的前提.如何确定和实现标记功能并使其支持多种安全政策是研究的目的.提出了一个安全标记公共框架,该框架基于静态客体标记和动态主体标记,引入了访问历史的概念,并给出了一个完备的标记函数集合.基于此框架,既可以实施多等级保密性安全政策,又可以实施多等级完整性安全政策.该框架在一个基于Linux的安全操作系统中的实现结果表明,基于该框架的安全系统在保证安全性的同时,还具有相当的灵活性和实用性.

关 键 词:标记  多级安全系统  信息流控制  保密性  完整性  安全操作系统
文章编号:1000-9825/2003/14(03)0547
收稿时间:2002/1/31 0:00:00
修稿时间:2002年1月31日

Design and Implementation of a Security Label Common Framework
LIANG Hong-Liang,SUN Yu-Fang,ZHAO Qing-Song,ZHANG Xiang-Feng and SUN Bo.Design and Implementation of a Security Label Common Framework[J].Journal of Software,2003,14(3):547-552.
Authors:LIANG Hong-Liang  SUN Yu-Fang  ZHAO Qing-Song  ZHANG Xiang-Feng and SUN Bo
Abstract:Labels are the foundation for implementing multilevel systems and the prerequisite of enforcing mandatory access control in secure systems. How to define and enforce label functions which support multiple security policies is the focus here. A security label common framework (SLCF) based on static object label and dynamic subject label is put forward. SLCF introduces the notation of access history and provides a complete label funtions set. Based on SLCF, both multilevel confidential policy and multilevel integrity policy can be expressed and enforced. SLCF is implemented in a secure operating system based on Linux, the experimental results show that the system based on SLCF is flexible and practicable.
Keywords:label framework  multilevel secure system  information flow control  confidentiality  integrity  secure operating system
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号