混合Biba和TE策略的强制完整性控制研究  

Research of the Mandatory Integrity Control Mixed Biba with TE Policy

在线阅读下载全文

作  者:林桥铿[1] 陈松政[1] 魏立峰[1] 

机构地区:[1]国防科学技术大学计算机学院,长沙410073

出  处:《中国电子商情(通信市场)》2012年第1期111-119,共9页

摘  要:针对Biba模型对主体和客体的完整级限制过于严格,兼容性和可用性低,以及为解决可用性而引入的可信主体访问权限和访问范围过大的问题,提出一种混合Biba和TE策略的强制完整性控制模型。该模型的完整性控制由Biba严格完整性策略实施,主体的权限通过TE策略所实现的访问隔离思想、最小权限原则和域转换能力进行控制,在提高Biba模型兼容性和可用性的同时,实现主体权限和访问范围的细粒度控制。The Biba model was over-strict in the limit of subject and object integrity level and had low compatibility and usability. The trusted subject introduced into the model had increased its usability but it was usually over authorized and much more vulnerable. In the paper, a mandatory integrity control model was proposed, which mixed Biba with TE(Type Enforcement) policy. In this model, integrity access control is carried out by Biba Strict Integrity Policy, and the subject's privilege is controlled by access isolation, least privilege and domain control which is achieved through TE. While improving the compatibility and usability of Biba, it also achieves a fine-grained access control in access permissions and access ranges.

关 键 词:完整性策略 强制完整性控制 BIBA模型 TE策略 

分 类 号:TP311.13[自动化与计算机技术—计算机软件与理论]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象