期刊文献+

多级安全OS与DBMS模型的信息流及其一致性分析 被引量:5

Information Flow Analysis and Consistency of Multilevel OS and DBMS Model
下载PDF
导出
摘要 数据库安全与操作系统安全密不可分,如果多级安全DBMS的安全策略不违反OS的安全策略,那么可以使用多级安全OS的安全机制来实现DBMS的部分安全功能,如强制访问控制.信息流分析使我们能更好地理解安全策略的意义和内容.该文给出了多级安全OS模型和以该模型为基础的多级安全DBMS模型,首次详细分析了它们在强制访问控制策略下的信息流集合.经过主客体的映射后,证明了数据库与操作系统的信息流集合是一致的,这个结论保证了利用OS的机制来实现DBMS的强制访问控制的合理性. The security of database system (DBMS) is closely related to security of operation system (OS). Multilevel security DBMS can implement its security functions, such as mandatory access control (MAC), using the mechanisms of multilevel security OS only when the security policy of DBMS not violate the security policy of OS. Information flow analysis is beneficial to understanding the meaning and content of the security policies. The theory of information flow analysis is introduced at first. Before discussing the information flows, the multilevel security OS model and multilevel security DBMS model are presented. Then the information flows allowed in multilevel security OS and multilevel security DBMS are analyzed for the first time. The methods of analysis in OS and DBMS are similar: After concluding the objects that contain information, all the information flows among those objects are discussed according to the operations in the OS and DBMS. Because any object of DBMS can be mapped to one or a group of objects in OS, the category set of DBMS is a subset of the category set of OS. Finally the set of DBMS's information flows is proved consistent with the one of OS's information flows based on the definition of the consistence between two information flow sets. The conclusion guarantees the soundness of implementing mandatory access control of multilevel security DBMS using the mechanisms of multilevel security OS.
出处 《计算机学报》 EI CSCD 北大核心 2005年第7期1123-1129,共7页 Chinese Journal of Computers
基金 国家"九七三"重点基础研究发展规划项目基金(G1999035802) 国家自然科学基金(60025205 60273027) 国家"八六三"高技术研究发展计划项目基金(2002AA141080)资助.~~
关键词 信息流 多级安全数据库 多级安全操作系统 一致性 多级关系模型 Computer operating systems Data flow analysis Database systems Information analysis Security systems
  • 相关文献

参考文献11

  • 1Denning D.E.. A lattice model of secure information flow. Communications of the ACM, 1976, 19(5): 236~243
  • 2Bertino E., de Capitani Di Vimercati S., Ferrari E., Samarati P.. Exception-based information flow control in object-oriented systems. ACM Transactions on Information and System Security, 1998, 1(1): 26~65
  • 3Samarati P., Bertino E., Ciampichetti A., Jajodia S.. Information flow control in object-oriented systems. IEEE Transactions on Knowledge and Data Engineering, 1997, 9(4): 524~538
  • 4Osborn S.L.. Information flow analysis of an RBAC system. In: Proceedings of the 7th ACM Symposium on Access Control Models and Technologies, Monterey, California, 2002, 163~168
  • 5Nyanchama M., Osborn S.L.. Information flow analysis in role-based security systems. In: Proceedings of the 6th International Conference on Computing and Information, Peterborough, Ontario, Canada, 1994
  • 6Elliott Bell D., LaPadula L.J.. Bell-LaPadula model for secure computer systems. The MITRE Corporation, Bedford, MA: Technical Report ESD-TR-75-306, 1976
  • 7Sandhu R.. Design and implementation of multilevel databases. In: Proceedings of the 6th RADC Workshop on Multilevel Database Security, Southwest Harbor, Maine, 1994, 1~5
  • 8Sandhu R., Chen F.. The multilevel relational (MLR) data model. ACM Transactions on Information and System Security, 1998, 1(1): 93~132
  • 9Notargiacomo LouAnna. Architectures for MLS database management systems. In: Information Security: An Integrated Collection of Essays, Essay 19. Los Alamitos: IEEE Computer Society Press, 1995, 439~459
  • 10Xu Zhen, Feng Deng-Guo. Architecture of SKLOIS multilevel secure DBMS.In:Proceedings of the CCICS'2003, Wuhan,2003, 334-328(in Chinese)(徐震,冯登国.SKLOIS多级安全数据库管理系统的体系结构.见:CCICS'2003论文集, 武汉, 2003, 334~328)

同被引文献48

引证文献5

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部