首页 | 官方网站   微博 | 高级检索  
     

基于轻量级虚拟化环境的可信多级安全容器机制
引用本文:吉晨,石勇,戴明,李晓勇.基于轻量级虚拟化环境的可信多级安全容器机制[J].计算机应用研究,2017,34(6).
作者姓名:吉晨  石勇  戴明  李晓勇
作者单位:北京交通大学 计算机与信息技术学院,北京交通大学 计算机与信息技术学院,中国交通通信信息中心,北京交通大学 计算机与信息技术学院
基金项目:中国铁路总公司科研项目(YS2016X-35);中国交通运输部科技项目(2015-362-208-430)
摘    要:传统的多级安全机制在实现时一般需要依赖安全操作系统,但最终证明这些多级安全系统在实际应用方面并不成功。针对目前多级安全机制实用性差的问题,提出一种基于轻量级虚拟化环境的可信多级安全容器机制。首先对系统安全域进行划分,提出一套多级安全策略规则,然后通过形式化方法证明其符合多级安全要求;最后通过联合文件系统技术和容器技术说明该机制的技术可行性,并对应用场景给出了说明。结果表明,本方法实现简单,应用范围广,可以有效改善多级安全机制实用性差的问题。

关 键 词:多级安全  虚拟化  形式化  安全策略  
收稿时间:2016/5/3 0:00:00
修稿时间:2017/4/10 0:00:00

A Trusted Multi-level Security Container Mechanism based on Lightweight Virtualization Environment
Ji Chen,Shi Yong,Dai Ming and Li Xiaoyong.A Trusted Multi-level Security Container Mechanism based on Lightweight Virtualization Environment[J].Application Research of Computers,2017,34(6).
Authors:Ji Chen  Shi Yong  Dai Ming and Li Xiaoyong
Affiliation:School of Computer and Information Technology,Beijing Jiaotong University,School of Computer and Information Technology,Beijing Jiaotong University,China Transport Telecommunications Information Center,School of Computer and Information Technology,Beijing Jiaotong University
Abstract:Traditional multi-level security mechanism usually depends on the safety of operating system, which has been finally proved to be not practical. In order to improve the applicability of the multi-level mechanism, a trusted multi-level security container mechanism based on lightweight virtualization environment has been proposed in this paper. This method firstly proposed a set of multi-level security policy rules based on the division of the system security domain. Then the policy was proved to be meeting the requirements of multi-level security by means of formal methods. Finally, this paper illustrated the technical feasibility of the mechanism by the union file system technology and container technology, and discussed the application scenarios. The results show that the method is simple to be achieved and has a wide application range. Also, the applicability of the multi-level security mechanism can be effectively improved.
Keywords:multi-level security  virtualization  formalization  security policy  
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号