Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2007, Vol. 33 ›› Issue (09): 52-54.

• Degree Paper • Previous Articles     Next Articles

Separation of Duty Model Based on Chinese Wall Security Policy

LIN Honggang1,2, DAI Zongkun1   

  1. (1. Information Security Institute, Sichuan University, Chengdu 610064; 2. School of Mathematics, Sichuan University, Chengdu 610064)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-05-05 Published:2007-05-05

基于Chinese Wall安全策略的职责分离模型

林宏刚1,2,戴宗坤1   

  1. (1. 四川大学信息安全研究所,成都 610064;2. 四川大学数学学院,成都 610064)

Abstract: Separation of duty (SoD) is a fundamental means for prevention of fraud and errors. Based on the Chinese wall security policy, a model of history-based separation of duty is implemented and it tracks the history of user’s previous permissions record, from which the current permissions assigned to can be determined. The formal description and analysis about the model has been done and the model has been proved a well in accordance with principle of SoD. The model inherits the advantage of Chinese Wall security policy and separation of duty, and provides a more perfect access control stratagem.

Key words: Separation of duty(SoD), Chinese Wall, Conflict role

摘要: 职责分离是一个系统最基本的防止欺骗和错误的手段。该文在Chinese Wall安全策略的基础上,实现了一种基于历史记录的职责分离模型,通过跟踪用户的历史权限记录来决定用户当前分配的权限从而实现职责分离,并对其进行了形式化描述和分析,证明其满足职责分离安全原理。该模型继承了Chinese Wall策略和职责分离安全原则的优点,能够提供更加完善的访问控制策略。

关键词: 职责分离, Chinese Wall, 角色冲突

CLC Number: