作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (23): 141-143,146. doi: 10.3969/j.issn.1000-3428.2011.23.048

• 安全技术 • 上一篇    下一篇

面向服务进程的用户权限隔离模型

李 瑜1,2,赵 勇1,2,梁 鹏1   

  1. (1. 北京工业大学计算机学院,北京 100124;2. 信息安全国家重点实验室(中国科学院软件研究所),北京 100049)
  • 收稿日期:2011-11-01 出版日期:2011-12-05 发布日期:2011-12-05
  • 作者简介:李 瑜(1983-),男,博士研究生,主研方向:信息安全,可信计算;赵 勇,讲师、博士;梁 鹏,博士研究生
  • 基金资助:
    国家“863”计划基金资助项目(2009AA01Z437);国家“973”计划基金资助项目(2007CB311100);信息安全国家重点实验室(中国科学院软件研究所)开放课题基金资助项目

User Permission Isolation Model Oriented to Service Process

LI Yu 1,2, ZHAO Yong 1,2, LIANG Peng 1   

  1. (1. College of Computer Science and Technology, Beijing University of Technology, Beijing 100124, China; 2. State Key Laboratory of Information Security(Institute of Software, Chinese Academy of Sciences), Beijing 100049, China)
  • Received:2011-11-01 Online:2011-12-05 Published:2011-12-05

摘要: 针对系统服务中的特权用户问题,提出一种面向服务进程的用户权限隔离模型,依据安全级别将用户、隔离域、程序模块进行映射关联,利用虚拟化技术为不同用户构造相互隔离的运行环境,形式化定义用户隔离域,给出虚拟化构建隔离域的关键技术及实现方法,从而实现用户权限的隔离,消除系统中潜在的特权用户。

关键词: 最小权限, 虚拟化, 隔离, 特权用户, 域, 系统服务

Abstract: In order to solve the unnecessary root users in the operating system services, a user permission isolation model is proposed. Based on the mapping link among users, isolated domains and program modules according to the security level, associated with the use of virtualization, isolated runtime environments are constructed for different users. The model gives formal definition of user isolated domain and the key mechanisms for its implementation. The model realizes least privilege principle for the isolated domain, and the paper gives the conclusion that potential root users are eliminated in the isolated domains.

Key words: least permission, virtualization, isolation, privileged user, domain, system service

中图分类号: