作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (09): 52-54.

• 博士论文 • 上一篇    下一篇

基于Chinese Wall安全策略的职责分离模型

林宏刚1,2,戴宗坤1   

  1. (1. 四川大学信息安全研究所,成都 610064;2. 四川大学数学学院,成都 610064)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-05-05 发布日期:2007-05-05

Separation of Duty Model Based on Chinese Wall Security Policy

LIN Honggang1,2, DAI Zongkun1   

  1. (1. Information Security Institute, Sichuan University, Chengdu 610064; 2. School of Mathematics, Sichuan University, Chengdu 610064)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-05-05 Published:2007-05-05

摘要: 职责分离是一个系统最基本的防止欺骗和错误的手段。该文在Chinese Wall安全策略的基础上,实现了一种基于历史记录的职责分离模型,通过跟踪用户的历史权限记录来决定用户当前分配的权限从而实现职责分离,并对其进行了形式化描述和分析,证明其满足职责分离安全原理。该模型继承了Chinese Wall策略和职责分离安全原则的优点,能够提供更加完善的访问控制策略。

关键词: 职责分离, Chinese Wall, 角色冲突

Abstract: Separation of duty (SoD) is a fundamental means for prevention of fraud and errors. Based on the Chinese wall security policy, a model of history-based separation of duty is implemented and it tracks the history of user’s previous permissions record, from which the current permissions assigned to can be determined. The formal description and analysis about the model has been done and the model has been proved a well in accordance with principle of SoD. The model inherits the advantage of Chinese Wall security policy and separation of duty, and provides a more perfect access control stratagem.

Key words: Separation of duty(SoD), Chinese Wall, Conflict role

中图分类号: