首页 | 官方网站   微博 | 高级检索  
     

基于推理树的XML推理控制研究
引用本文:徐铮,陈恭亮,李建华.基于推理树的XML推理控制研究[J].通信技术,2015,48(2):208-213.
作者姓名:徐铮  陈恭亮  李建华
作者单位:1.上海交通大学 信息安全工程学院,上海 200240;2.上海交通大学 电子信息与电气工程学院, 上海 200240
基金项目:国家自然科学基金项目(No 61271220)~~
摘    要:信息安全中的推理问题是指攻击者根据合法获得的信息,利用信息之间关联,推理出不能直接访问的信息,从而造成敏感信息泄露的一种安全问题。推理控制是对信息间的这种联系加以控制,防止敏感信息的推理泄露。XML是当前信息技术中最重要的信息载体之一,是Internet中数据交换和传输的默认标准,也是传统关系数据库的有力竞争者。文中研究了XML数据库中信息的推理控制问题,定义了信息以及信息的规范化表示,针对XML数据库中敏感信息的推理泄露,引入了推理树的概念,提出了一种新的推理通道的刻画方法,并提出了相应的动态推理控制策略,在保证信息安全的基础上,使文档中的信息最大可用。

关 键 词:XML  推理通道  推理控制  

Inference Control of XML based on Inference Tree
XU Zheng;CHEN Gong-liang;LI Jian-hua.Inference Control of XML based on Inference Tree[J].Communications Technology,2015,48(2):208-213.
Authors:XU Zheng;CHEN Gong-liang;LI Jian-hua
Affiliation:(1.School of Information Security Engineering, Shanghai Jiao Tong University,Shanghai 200240,China;2.School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai 200240,China);
Abstract:Inference in information security is a problem of indirect disclosure of sensitive information,that is,the adversary takes advantage of the correlations among information and deduces the inaccessible information. Inference control aims to control the correlation among information, and further to prevent inference disclosure of sensative information.XML, as one of the most essential information carriers in information technology, is the agreed standard of Internet data exchange and transmission, and also the competative rival of tranditional relational database. Inference control of XML database is studied, information and its standardized expression defined.Aiming at the inference leakage of sensative information in XML database, the concept of inference tree is introduced, a novel inference channel proposed, and a relative dynamic inference control stratagy also suggested to balance the contradiction between security and availability of XML documents.
Keywords:XML  inference channel  inference control  
本文献已被 CNKI 等数据库收录!
点击此处可从《通信技术》浏览原始摘要信息
点击此处可从《通信技术》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号