A new formal model for privilege control with supporting POSIX capability mechanism  被引量:3

A new formal model for privilege control with supporting POSIX capability mechanism

在线阅读下载全文

作  者:JIQingguang QINGSihan HEYeping 

机构地区:[1]EngineeringResearchCenterforInformationSecurityTechnology,InstituteofSoftware,ChineseAcademyofSciences,Beijing100080,China

出  处:《Science in China(Series F)》2005年第1期46-66,共21页中国科学(F辑英文版)

基  金:supported by the National Key Basic Research Program of China(Grant No.G1999035802);the National Natural Science Foundation of China(Grant No.60083007)

摘  要:In order to enforce the least privilege principle in the operating system, it is necessary for the process privilege to be effectively controlled; but this is very difficult because a process always changes as time changes. In this paper, based on the analysis on how the process privilege is generated and how it works, a hierarchy implementing the least privilege principle with three layers, i.e. administration layer, functionality control layer and performance layer, is posed. It is clearly demonstrated that to bound privilege's working scope is a critical part for controlling privilege, but this is only mentioned implicitly while not supported in POSIX capability mechanism. Based on analysis of existing control mechanism for privilege, not only an improved capability inheritance formula but also a new complete formal model for controlling process based on integrating RBAC, DTE, and POSIX capability mechanism is introduced. The new invariants in the model show that this novel privilege control mechanism is different from RBAC's, DTE's, and POSIX's, and it generalizes subdomain control mechanism and makes this mechanism dynamic.

关 键 词:formal model least privilege ROLE DOMAIN capability. 

分 类 号:TP316.81[自动化与计算机技术—计算机软件与理论] TP309[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象