摘要
XML应用的不断扩展带来了XML安全的需求.目前关于XML安全性的研究主要集中于自主访问控制、基于角色的访问控制和视图技术,而对于强制访问控制的研究较少.提出一个改进的XML文档的强制访问控制模型.模型建立了XML文档的多级安全完整性性质.为避免结构约束与完整性约束可能产生隐通道,模型提出"滞后删除"策略.对XQuery和XUpdate的主要操作进行语义描述,并对模型的安全性进行分析.
XML's increasing popularity highlights the security need for XML documents. Researchers have paid more attention on discretional access control, role-based access control and view based technology, rather than mandatory access control. A improved mandatory access control model for XML is presented in the paper. The integr!ty properties for multilevel XML document are proposed in the paper. A novel approach "delayed-removing" is introduced in order to avoid covert channel. In the paper, the manipulation rules for typical operation of XQuery and XUpdate are created, and the security of the model is discussed.
出处
《小型微型计算机系统》
CSCD
北大核心
2009年第6期1043-1048,共6页
Journal of Chinese Computer Systems
基金
国家自然科学基金项目(60703048)资助
关键词
XML
多级安全
多级完整性
隐通道
XML
multilevel security
multilevel integrity
covert channel