通信学报
通信學報
통신학보
JOURNAL OF CHINA INSTITUTE OF COMMUNICATIONS
2010年
2期
100-106
,共7页
信息安全%BLP模型%完整性%多级安全
信息安全%BLP模型%完整性%多級安全
신식안전%BLP모형%완정성%다급안전
information security%BLP model%integrity%multilevel security
在BLP模型的基础上,提出了BLP模型的一个完整性增强模型--EIBLP模型.该模型在不改变BLP模型信息流方向(下读上写)的基础上对上行信息流增加了必要的限制,并对BLP模型安全公理、主客体访问控制标签、访问控制操作模式以及状态转移规则进行了改进,且对该模型的安全性进行了分析并给出了证明.结果表明,改进后的EIBLP模型不仅仍然满足BLP模型的基本安全特性,而且通过改进BLP模型信息上行约束条件、主客体的安全标签、扩展模型操作模式、完善模型状态转移规则等方法,有效提高了BLP模型的完整性,并在一定程度上提高了机密性.
在BLP模型的基礎上,提齣瞭BLP模型的一箇完整性增彊模型--EIBLP模型.該模型在不改變BLP模型信息流方嚮(下讀上寫)的基礎上對上行信息流增加瞭必要的限製,併對BLP模型安全公理、主客體訪問控製標籤、訪問控製操作模式以及狀態轉移規則進行瞭改進,且對該模型的安全性進行瞭分析併給齣瞭證明.結果錶明,改進後的EIBLP模型不僅仍然滿足BLP模型的基本安全特性,而且通過改進BLP模型信息上行約束條件、主客體的安全標籤、擴展模型操作模式、完善模型狀態轉移規則等方法,有效提高瞭BLP模型的完整性,併在一定程度上提高瞭機密性.
재BLP모형적기출상,제출료BLP모형적일개완정성증강모형--EIBLP모형.해모형재불개변BLP모형신식류방향(하독상사)적기출상대상행신식류증가료필요적한제,병대BLP모형안전공리、주객체방문공제표첨、방문공제조작모식이급상태전이규칙진행료개진,차대해모형적안전성진행료분석병급출료증명.결과표명,개진후적EIBLP모형불부잉연만족BLP모형적기본안전특성,이차통과개진BLP모형신식상행약속조건、주객체적안전표첨、확전모형조작모식、완선모형상태전이규칙등방법,유효제고료BLP모형적완정성,병재일정정도상제고료궤밀성.
A model which enhances the integrity of BLP model was presented based on the BLP model. This model was called as EIBLP model. Some necessary restraints to upward information flow were appended in EIBLP without chang-ing the information flow direction (down-read and up-write) of BLP model and the security axiom, access labels of sub-ject and object, access control operation mode, and state transition policy of BLP model were improved. And then, ana-lyzes the security of EIBLP was analyzed and proved. It shows that the improved EIBLP model not only satisfies com-pletely the basic security of BLP, but also enhances the integrity of BLP with improving the upward restraints, the subject and object access labels, the model operation mode, and the model state translation rules. At the same time, the improved EIBLP raises the confidentiality of BLP at a certain extent.