期刊文献+

基于信息密级标识的多级域防护系统

Multi-level domain protection system based on Information security classification iden-tifies
原文传递
导出
摘要 如何有效控制不同安全域之间的信息流向以及信息的访问控制是分级保护的一个工作重点。该系统利用Windows内核的驱动框架,通过嵌入在I/0管理器和文件系统驱动模块之间的文件过滤驱动模块向信息头部写入密级标,并结合管理中心分发的密钥,实现信息的动态透明加/解密,使涉密文件只能被有相应权限的用户所访问;信息控制引擎结合访问控制策略,实现信息流向控制,杜绝高密级信息向低密级域流动。 How to effectively control the flow of information between different security domains,and access control information is classified protection a pdority.The system utilizes windows kernel driver framework,embedded file system filter driver module between I/O manager and file system driver module. File system filter driver module writing secrets level identification to the head of information,and combines management center to distribute the key, to achieve dynamic and transparent en-crypted/decrypted,so that confidentital information can only be accessed by user with have appropriate permissions;Information control engine combines access control pol-icy, to achieve control of the flow of information,and put an end to high-security classification information flow to the low-level domain.
出处 《网络安全技术与应用》 2013年第2期27-30,共4页 Network Security Technology & Application
关键词 安全域 密级标识 过滤驱动 访问控制 Secure domain Secudty classification identifies Filter driver Access Control
  • 相关文献

参考文献2

二级参考文献6

  • 1Rajeev Nagar.Windows NT file system internals:a developer's guide[M].Cambridge:O'Reilly,1997.
  • 2Wright C P,Dave J,Zadok E.Cryptographic file systems performance:what you don't know can hurt you[A].Security in Storage Workshop,2003.SISW '03[C].Proceedings of the Second IEEE International 31-31 Oct.2003,47-47.
  • 3Oney Walter.Programming the icrosoft windows driver model[M].Redmond,Wash.:Microsoft Press,2003.
  • 4Mark E Russinovich,David A Solomon.Microsoft windows internals fourth edition[M].Redmond Wash:Microsoft Press,2005.
  • 5Lipmaa H,Rogaway P,Wagner D.Comments NIST concerning AES modes of operations:CTR-mode encryption[C].Symmetric Key Block Cipher Modes of Operation Workshop Baltimore Maryland US,20 October 2000.
  • 6FIPS Pub 197.Advanced encryption standard (AES) federal information processing standards publication 197[D].US Department of Commerce/N.I.S.T,Springfield,Virginia,November 26,2001.

共引文献28

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部