操作系统安全结构框架中应用类通信安全模型的研究  被引量:6

Research on an Application Class Communication Security Model on Operating System Security Framework

在线阅读下载全文

作  者:郑志蓉[1,2] 蔡谊[1,2] 沈昌祥 

机构地区:[1]海军工程大学电气工程系,武汉430003 [2]海军计算技术研究所,北京100841

出  处:《计算机研究与发展》2005年第2期322-328,共7页Journal of Computer Research and Development

基  金:国家"九七三"重点基础研究发展规划基金项目 (G19990 3 5 80 1)

摘  要:经典的BLP模型是解决保密性问题的理论基础 ,Biba模型是一种简明易实现的完整性模型 在应用系统中数据的共享和安全是一对矛盾 在将应用系统抽象为应用类的基础上 ,引入完整性规则集代表信息的可信度 ,结合BLP模型和Biba模型构造了一种应用类通信的安全模型 ,并给出了模型的形式化描述和正确性证明 应用类通信安全模型不仅解决了保密性问题 ,而且解决了完整性问题 以支持B/S文电传输应用系统的安全为例 ,给出了在操作系统中实现应用类通信安全模型的方法 。The classical BLP model is recognized as the theoretical foundation of solving confidentiality problem. Biba model of solving integrity is easily realized in secure computer systems. In order to solve the contradiction between information sharing and security in the application system, a new application class communication security model is constructed theoretically based on the abstraction of application class. The new model introduces integrity rules to measure the trust level of sharing information between different application classes, thus combining BLP model and Biba model with no conflict. A formal description and verification on the model is detailed, which provides both the confidentiality and integrity for the system. With the development of a secure file transfer application system, which is based on the browser/server application pattern, the way to implement the new model in the Linux operating system is described and the performance of the system is discussed.

关 键 词:操作系统 应用类 BLP模型 BIBA模型 B/S应用 

分 类 号:TP309[自动化与计算机技术—计算机系统结构] TP316[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象