摘要
XML应用的不断扩展带来了XML安全的需求。目前关于XML安全性的研究主要集中于自主访问控制、基于角色的访问控制和视图技术,而对于强制访问控制很少有研究。对多级安全XML文档的元素删除操作进行了研究。由于在结构完整性约束和实体完整性约束下,低安全等级用户的元素删除操作可能导致高安全等级数据失去可用性或者产生信息隐通道,为此提出了一个滞后删除策略,并描述了该策略的完整性性质及实现。
XML's increasing popularity highlights the security discretional access control,role-based access control and view need for XML documents.Researchers have paid more attention on based technology,rather than mandatory access control.This paper focuses on the REMOVE operation of multilevel XML under the constraint of the hierarchy and the integrity.A novel policy "delayed-removing" is proposed which can avoid convert channel and keep the availability and the secrecy of higher level data element while removing the lower level data element.The integrity constraint and the implement of the policy are also detailed.
出处
《计算机工程与应用》
CSCD
北大核心
2008年第22期166-168,191,共4页
Computer Engineering and Applications
关键词
XML
多级安全
完整性
可用性
隐通道
XML
multilevel security
integrity
availability
covert channel