作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (08): 117-119. doi: 10.3969/j.issn.1000-3428.2012.08.038

• 安全技术 • 上一篇    下一篇

基于可信等级的BLP改进模型

池亚平 1,樊 洁 1,2,程代伟 1   

  1. (1. 北京电子科技学院通信工程系,北京 100070;2. 西安电子科技大学通信学院,西安 710071)
  • 收稿日期:2011-08-08 出版日期:2012-04-20 发布日期:2012-04-20
  • 作者简介:池亚平(1969-),女,副教授、硕士、CCF高级会员,主研方向:可信计算,网络安全;樊 洁,硕士研究生;程代伟,副教授、硕士
  • 基金资助:

    国家自然科学基金资助项目(60951001);国家科技支撑计划基金资助项目(2009BAH52B06);北京市自然科学基金资助项目(4102057);发改委信息安全产品产业化专项基金资助项目([2009] 1886)

Improved BLP Model Based on Trusted Level

CHI Ya-ping1, FAN Jie 1,2, CHENG Dai-wei1   

  1. (1. Department of Communication Engineering, Beijing Electronic and Science Technology Institute, Beijing 100070, China; 2. School of Communication, Xidian University, Xi’an 710071, China)
  • Received:2011-08-08 Online:2012-04-20 Published:2012-04-20

摘要: BLP模型存在完整性保护缺失、可信主体定义不明确和未考虑平台环境因素等问题。为此,提出一种基于可信等级的BLP改进模型TL-BLP。该模型引入主客体和平台的可信等级,并对BLP模型安全特性、主客体的敏感标记和状态转移规则进行改进,从而实现可信度的动态度量,保证访问操作平台的安全性,通过对BLP模型“下读上写”的限制,保证信息的完整性。分析结果表明,TL-BLP在保证信息机密性的基础上,能提高系统的完整性和可用性,实现基于可信度的访问控制。

关键词: BLP模型, 多级安全, 可信平台, 可信等级, 访问控制

Abstract: There are some problems in Bell-La Padula(BLP) model, including the loss of integrity protection, the indetermination of trusted subject and the neglect of the environment factors of the platform, so this paper proposes an improved BLP model based on trusted level, which is named TL-BLP. In TL-BLP, security property, sensitive label of subject and object, and state transfer rules are improved by introducing the trusted level of subject, object and platform. It realizes the dynamic measurement of trusted degree and ensures access platform security, and protects the information integrity by the restriction to “read down and write up”. Analysis shows that the model not only can ensure the confidentiality, but also can enhance the integrity and availability of the system effectively, and it implements the access control based on trusted degree.

Key words: Bell-La Padula(BLP) model, multi-level security, trusted platform, trusted level, access control

中图分类号: