检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:张明西[1,2] 韦俊银[1] 张相峰[3] 王以刚[1] 刘晖[1,2]
机构地区:[1]东华大学计算机科学与技术学院,上海201620 [2]东华大学纺织面料技术教育部重点实验室,上海201620 [3]中国科学院软件研究所,北京100080
出 处:《小型微型计算机系统》2011年第4期656-661,共6页Journal of Chinese Computer Systems
基 金:国家自然科学基金项目(90718027)资助;高等学校纺织生物医用材料学科创新引智计划项目(B070204)资助
摘 要:B iba模型的严格完整性策略能够保证数据的完整性,但是其静态实施可能降低系统的兼容性.在B iba模型严格完整性策略基础上提出了主体完整性标记动态确定方案.将主体完整性等级扩展为独立的读写区间,根据主体读写历史调整主体可读写的区间,在保护系统完整性的同时提高了系统的兼容性.给出了形式化证明,说明该方案是安全的.指出了现行改进方案中存在的安全隐患及导致该隐患的原因,通过对比分析说明动态确定方案能够消除该安全隐患.Strict Integrity Policy (SIP) of Biba model can be used to maintain the integrity of data in computer systems, but it might deny some non-malicious access requirements and hence decreases the compatibility of applications. A dynamic determination scheme of subject's integrity level which based on the subject's history behavior is presented, which can increase the compatibility of the software while keeping system integrity as strictly as SIP can. And the proof of it is also given, which shows that the improved SIP is secure. The security risk of the existing improved SIP which is resolved in our scheme is indicated by an example after comparison and analysis, and the main reason which leads to this phenomenon is also demonstrated.
分 类 号:TP311[自动化与计算机技术—计算机软件与理论]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.113