摘要
传统的自主访问控制不能提供足够的安全,而已有的强制访问控制模型规则过于严格,导致在公文流转时应用困难.提出一种适用于公文流转的强制访问控制模型,可满足机密性和完整性要求;融合自主访问控制的灵活性和强制访问控制的安全性;实现受控信息的双向流动.使用不干扰理论证明了模型的安全性.
Traditional discretionary access control can't provide adequate security. Rules of existing mandatory access control models are very rigid, and barriers in document flow occur. We propose a mandatory access control model is proposed which is suitable for document flow. In this model the requirements of both integrity and confidentiality are met. Flexibility of discretionary access control integrates with security of mandatory access control. Through checking the rules, information can flow bidirectionally. The security of the model is proved on the basis of noninterference theory.
出处
《北京工业大学学报》
EI
CAS
CSCD
北大核心
2010年第5期694-697,共4页
Journal of Beijing University of Technology
基金
国家'九七三'发展规划项目资助(2007CB307101)
国家'八六三'高技术研究发展计划项目资助(2007AA01Z410
2007AA01Z177
2009AA012437)
长江学者和创新团队发展计划项目资助(IRT0707)
国家自然科学基金项目资助(60973112)
北京工业大学博士启动基金项目资助(X0007999200901)
关键词
多级安全
访问控制
机密性
完整性
灵活性
multilevel security
access control
confidentiality
integrity
flexibility