摘要
基于信息流的安全模型较访问控制模型优势在于更本质的描述了什么是安全,自提出信息流的无干扰概念以来信息流模型就成为安全研究的中心之一,并提出了很多种无干扰模型。针对现存几种安全模型存在建模工具与分析工具不一致、不支持多级安全系统等问题。在广义无干扰模型以及聚合属性的基础上提出一种支持多级安全系统、多等级信息流策略状态转换且包含聚合属性的信息流安全模型,并给出了信息流策略的正式语义。
Compared with security models based on access control, security models based on information flow theory are more fundamental to capture the essentials of what is confidentiality. Since the definition of the concept of non-interference, varitations of non-interference models are presented. According to the existing security model existence of moden tools and analysis tools are inconsistent and does not support multi-level security system. A flow model that support multi-level security system and data aggregation based on wild Non-interfere model and aggregation properties is presented. Finally, a semantice for those information flow policies is given.
出处
《计算机工程与设计》
CSCD
北大核心
2009年第21期4848-4850,4952,共4页
Computer Engineering and Design
关键词
数据聚合
信息流
无干扰
多级安全
安全模型
date aggregation
information flow
non-interference
multi-level security
security model