检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]国防科学技术大学计算机学院,湖南长沙410073
出 处:《计算机工程与设计》2010年第12期2679-2682,共4页Computer Engineering and Design
基 金:国家863高技术研究发展计划基金项目(2007AA01Z461)
摘 要:基于角色提出并实现了一个用户权力限制模型。该模型通过角色授权控制,缺省不赋予登录用户任何特权。当用户操作或应用需要特权时,根据操作需求提升权限,并且一次有效;操作结束后,特权及时撤销。模型实现时,通过在用户与系统之间建立可信路径来防止权限提升过程中恶意程序进行篡改和窃取;通过改进访问控制列表检查算法减少了不必要的权限提升。用户权力限制模型能让用户更加安全、方便地控制系统,并有效地解决了用户权力最小化问题。A model of user right confinement(URC) based on roles is proposed and implemented.Under this model,the login user can not own any privilege by default via the role-based authorization control.The privilege would be promoted properly when it is required by an operation of the user or an application;however,it is available only once and would be disposed as soon as the operation had been finished.In order to protect the system from compromising and thieving by the malware,a trusted path between the user and system is set up during privilege-promotion.To reduce the frequency of unnecessary promotion the access control list check algorithm is improved.The URC model resolves the problem of minimizing user right effectively and presents a more secure and more convenient system envi-ronment to the user.
关 键 词:用户权力限制 最小特权 权限提升 访问控制框架 可信路径
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.148.192.32