作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (4): 134-137. doi: 10.3969/j.issn.1000-3428.2010.04.047

• 安全技术 • 上一篇    下一篇

一种结合用户许可的多级安全策略模型

卢小亮,郁 滨   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2010-02-20 发布日期:2010-02-20

Multilevel Security Policy Model Combined with User Permission

LU Xiao-liang, YU Bin   

  1. (Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2010-02-20 Published:2010-02-20

摘要: 针对BLP模型存在“向上写”规则破坏数据完整性、主体分配权限过大及客体安全等级不变的问题,提出一种结合用户许可的多级安全策略模型。该模型利用可信度标识对主体写操作进行完整性保护,通过用户许可标识解决BLP模型和可信度标识存在的主体分配权限过大问题,结合系统管理员仲裁机制对修改的客体安全等级进行动态调整。理论分析表明,该模型能够保证系统的安全。

关键词: 安全模型, 可信度标识, 用户许可

Abstract: Aiming at the problem that BLP model’s access rule of “no write down” destroy data integrity, subject has most privilege and object holds constant security level, this paper presents a multilevel security policy model combined with user permission. In the model, trusted label is used in subject writing to protect object integrity. User permission solves the problem that subject privilege in BLP model and trusted label has more rights to steal data. By importing arbitration for system administrator, confidential label and trusted label for the modified objects is adjusted dynamically. Theory analysis indicates that the model can assure system security.

Key words: security model, trusted label, user permission

中图分类号: