摘要
由于缺乏信息流控制机制,RBAC模型的授权访问可能导致不安全的信息流.为了保护RBAC模型系统中信息的机密性,定义了RBAC模型的非法信息流概念,给出了非法信息流的检测、更新以及控制算法。将这些算法用于RBAC模型的授权管理可有效防止信息的非授权泄漏,实现安全的访问。
Due to lock the mechanism of controlling information flow, the authorized accesses of RBAC model may lead to insecure information flow. To protect confidentiality of information in RBAC model systems, the concept of illegal information flow is defined, algorithms of detecting, renewing and controlling illegal information flow are proposed. These algorithms can prevent effectively unauthorized information leakage, realize secure aceesses.
出处
《计算机科学》
CSCD
北大核心
2008年第8期65-68,89,共5页
Computer Science
基金
国家"863"高技术研究发展计划基金项目(2005AA147050)
关键词
RBAC
非法信息流
引发用户
威胁用户
RBAC, Illegal information flow, Users of inducing, Users of threatening