首页 | 官方网站   微博 | 高级检索  
     

基于任务划分的防信息聚合泄密模型
引用本文:解文冲,杨英杰,汪永伟,代向东.基于任务划分的防信息聚合泄密模型[J].计算机应用,2013,33(2):408-416.
作者姓名:解文冲  杨英杰  汪永伟  代向东
作者单位:1. 河南省信息安全重点实验室(信息工程大学),郑州 4500042. 信息工程大学,郑州 450004
摘    要:针对BLP模型中存在的信息聚合泄密、可信主体权限过大以及模型完整性缺失的问题,结合文件分级保护的需求,提出了基于任务划分的防信息聚合泄密模型IALP。首先,探讨了信息聚合形成的原因及研究现状;然后,以任务划分为基础,对主体的信息可知度及客体所占信息权重进行量化,提出了相对可信主体的概念,给出了模型安全公理和状态转换规则。最后,经理论证明、应用举例和分析表明,该模型能够控制主体对具有聚合泄密关系的客体集合的可知程度,并在一定程度上限制可信主体权限以及增强完整性。

关 键 词:文件分级保护  Bell-LaPadula  (BLP)模型  信息聚合  可信主体  完整性  
收稿时间:2012-08-27
修稿时间:2012-10-16

Information aggregation leakage proof model based on assignment partition
XIE Wenchong , YANG Yingjie , WANG Yongwei , DAI Xiangdong.Information aggregation leakage proof model based on assignment partition[J].journal of Computer Applications,2013,33(2):408-416.
Authors:XIE Wenchong  YANG Yingjie  WANG Yongwei  DAI Xiangdong
Affiliation:1. Henan Province Key Laboratory of Information Security (Information Engineering University), Zhengzhou Henan 450004, China2. Information Engineering University, Zhengzhou Henan 450004, China
Abstract:To solve the problems existing in BLP (Bell-LaPadula) model, such as information aggregation leakage, excessive privileges of trusted subject and the deficiency of integrity, with reference to the application requirement of hierarchical file protection, an information aggregation leakage proof model named IALP (Information Aggregation Leakage Proof) was proposed based on assignment partition. First of all, the cause of information aggregation leakage and the current research situation were discussed. Secondly, on the basis of assignments partition, the knowledgeable degree of subject and the information weight of object were quantized, and the relatively trusted subject was proposed. Security axioms and state transition rules were given. Finally, the theoretical proof, application examples and analysis indicate that IALP can control the knowable degree of the subject towards the object set with the aggregation leakage relation, and limits the privilege of trusted subject and enhances the integrity to some extent.
Keywords:hierarchical file protection                                                                                                                          Bell-LaPadula (BLP) model                                                                                                                          information aggregation                                                                                                                          trusted subject                                                                                                                          integrity
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号