基于可信计算的区域边界防护模型研究与应用  被引量:5

Research and Application on Model of Secure Area Boundary Protection Based on Trusted Computing

在线阅读下载全文

作  者:姚崎[1] 

机构地区:[1]北京天融信公司,北京100085

出  处:《信息安全与技术》2010年第6期71-75,79,共6页

基  金:国家"863"计划资助项目(2007AA01Z410);北京市科委研发攻关类资助项目(Z07000100720705)

摘  要:依据信息系统等级保护安全设计技术要求的框架,提出一种基于可信计算的安全区域边界防护模型。在模型中,运用可信平台三元对等鉴别技术,解决了区域边界防护网关自身完整性鉴别问题;采用可信网络连接建立与传递技术,实现了跨区域边界网络访问的全程可信;采用区域边界代理和控制策略分布执行的方式,实现了基于主客体的区域边界自主访问控制策略。According to framework of 'Technical requirements of security design of the classified protection information system', a model of the security area boundary protection based on trusted computing is proposed. In the model, by using technology of Tri-element Peer Authentication in trusted platform, the problem of identification of area boundary protection gateway was solved. By using technology of establishment and transfer of trusted network connection, all of the nodes were trusted in the path of network access across the area boundary. By using the technology of area boundary agents and distributed implementation of access control, discretionary access control policy based on object and subject was achieved.

关 键 词:等级保护 可信计算 可信网络连接 访问控制 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象