摘要
提出通过融合RBAC和TE模型来实现Clark-Wilson模型的一种方法,即:通过不同用户赋予不同角色实现责任分立;利用特殊的域表示变换过程;使用不同的类型标识约束数据项和非约束数据项.分析了实施和认证规则的正确性.通过在SEBSD系统中实施了FTP的完整性安全策略的实例,说明该方法能够实现细粒度的访问控制和灵活配置.
An approach to enforce Clark-Wilson model in the combination of RBAC and TE models is presented,namely:separation of duties is addressed by assigning different roles to different users;special domains are used for representing transformation procedures;and the constrained data items and unconstrained data items are labeled with different types.The correctness of the enforcement and certification rules is analyzed.A detailed case study of FTP integrity policy is implemented under SEBSD,and shows that the approach achieves fine-grained access control and flexible configuration.
出处
《中国科学院研究生院学报》
CAS
CSCD
北大核心
2010年第4期538-546,共9页
Journal of the Graduate School of the Chinese Academy of Sciences
基金
Supported by National 863 Hight-tech Research Development Program of China (2006AA01Z451,2007AA010505,and 2009AA01Z432)