作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (1): 171-173.

• 安全技术 • 上一篇    下一篇

通用准则评估综述

刘伟 1,2,张玉清1,2, 冯登国 1,2   

  1. 1.信息安全国家重点实验室中国科学院研究生院,北京 100039;2.中国科学院研究生院国家计算机网络入侵防范中心,北京 100039
  • 出版日期:2006-01-05 发布日期:2006-01-05

Survey of Common Criteria Evaluation

LIU Wei1,2 , ZHANG Yuqing1,2, FENG Dengguo1,2   

  1. 1. State Key Laboratory of Information Security, Graduate School of Chinese Academy of Sciences, Beijing 100039;2. National Computer Network Intrusion Protection Center, Graduate School of Chinese Academy of Sciences, Beijing 100039
  • Online:2006-01-05 Published:2006-01-05

摘要: 在介绍CC 国内外发展现状的基础上,系统地分析了通用准则CC 的基本概念、主要思想以及CC 评估角色和类型等主要问题,并对CC 评估配套方法——CEM 及其评估流程进行了深入探讨,最后在总结CC 评估现状的基础上,指出了CC 评估所存在的问题及其未来的发展趋势。

关键词: 通用准则;通用评估方法;评估对象;保护轮廓;安全目标

Abstract: Common criteria (CC) is the world most comprehensive evaluation criteria for the security of information technology. Based on the introduction to the development of CC home and abroad, the paper analyzes systematically the basic concepts of CC, its main idea, and evaluation roles and types. It also discusses a method named CEM and its evaluation flow in detail. Finally, the paper presents some existing problems and future research trend of CC evaluation on the basis of a summary of CC evaluation status

Key words: Common criteria (CC); Common evaluation methodology (CEM); Target of evaluation(TOE); Protect profile (PP); Security target(ST)