摘要
随着访问控制技术的发展以及安全需求的多样化,访问控制模型的组合应用日益成为安全操作系统设计的重要目标,由此对策略描述语言提出了统一易用的新要求。通过对现有安全策略语言和访问控制模型的研究,设计了一种应用于安全操作系统领域的访问控制策略语言EGACPL(Easily Use andGeneral Access Control Policy language)。EGACPL采用结构化以及面向对象的设计思想,便于开发者理解和使用;统一描述策略元素和安全规则,支持多种访问控制模型,体现了良好的通用性。
With the development of access control technology as well as the diversity of security requirements,the combination of access control model in application is increasingly becoming an important security goal in the design of operating system,which gives new requirements for the unification and case application of the policy description language.Based on the research of the existing security policy language and access control model,this paper presents an access control policy language EGACPL.With the application of structuralized and object-oriented design,EGACPL is easy for developers to understand and use.It unifies the description of policy elements and security rules to support a wide range of access control model,which shows better generality.
出处
《计算机系统应用》
2010年第3期39-44,共6页
Computer Systems & Applications
基金
电子信息产业发展基金(财建[2008]329
工信部运[2008]97)
关键词
安全操作系统
访问控制
策略语言
面向对象
security operating system
access control
policy language
object-oriented