详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
According to the GB17859-1999, the information system can be divided into five classes.The strength of security policy and security mechanism in different classes increases from thefirst one, which is called “level protection”. It is considered as the basic rule of our informationsecurity. Access control is the basic and direct way of realizing the important informationresources protection, as well as the primary aspect of “level protection”. However, the currentaccess control model and method can not effectively solve such problems as the intrasystem andintersystem irregular indirect access, resulting in the serious indirect risk of informationrevelation. Therefore, against the background of Cross-Multi-Class information system, thispaper originates a series of access control models, which works in different classes andinterconnection modes. In addition, security entropy is put forward, based on which, the securityof the model is proved. Specifically, the main contents of this paper are as below:
     1. In order to solve the problem of security proof of access control in multi-class interconnection system,a security entropy-based quantitative analysis theory is proposed. Firstly, the policy security entropy is definedaccording to the weighted entropy in the information theory, and uncertainties calculate method is put forwardto determine the irregular access behaviors. Secondly, aiming at the direct violation, flow violation and indirectviolation, calculation method for security entropy are proposed respectively. Besides, weighs option method isgiven based on availability and confidentiality. Thirdly, based on the security entropy, the method ofdetermining the possibility of irregular access is presented. With the quantitative analysis of the typical accesscontrol model, the effectiveness of this method is verified, and the insufficient of the current model isindicated.
     2. Based on the security entropy theory, the subsystem security theorem in different classesand different interconnection modes in multi-class interconnection system is proposed. Firstly,class-protection is analyzed, the security conditions of two, three, and four-class subsystemunder non-interconnection mode are proposed in the form of security entropy, laying thefoundation for the security certification of the single subsystem state machine. Then, securityentropy is extended, and the concept of the united security entropy is proposed. Based on theunited security entropy theory, the security theorem of the multi-class access control system usedin different interconnection modes is presented, laying the theoretical foundation for the securitycertification of the multi-class interconnection access control model.
     3. The single-class access control model based on信息流强约束is put forward, and theproblem of intrasystem irregular indirect information stream is solved. Firstly, the method ofaccess security based on the information stream graph is raised. Then, based on the information stream graph, users’ indirect irregular accesses are strongly constrained. Secondly, thesingle-class subsystem state machine is modeled, as well as the system state, the state conversionrule, the auto machine and the system are defined. In addition, security theorems of the systemstate, the state conversion rule, the auto machine and the system are given, and their security isproved. Finally, the realization of rules for the two, three and four-class subsystem state machineis proposed, and its security is proved.
     4. Based on the united control, the article puts forward the multi-class interconnectionaccess control model, through which, risks such as cross-class irregular indirect informationstream, wrong information flow, counterfeiting of user’s security identifiers in the multi-classinterconnection system is solved. Firstly, the multi-class interconnection access control system ismodeled, and security domain, system class, trust matrix, interconnection mode andadministrator are added. Besides, the multi-class interconnection system is described completely.Secondly, The security theorem of multi-class interconnection access control model is given.Based on multi-class information stream graph, through the united control of users’cross-domain and cross-class access, the consistency of different class subsystem controlirregular access is kept. Thirdly, based on the security entropy theory, the security of the modelis proved. Finally, the rule set of subsystem state machine in six classes is given, which cansupport the multi-class interconnection system in different interconnection model.
     In conclusion, an access control theory system suited to multi-class interconnection systemis formed in this paper, which provides the theoretical foundation for the security informationsharing in the information system of different interconnection modes and security classes.
[1]BELL D E,LAPADULA L J.Secure Computer Systems:Mathematical Foundations[R].Technical Report M74—244,The MITRE Corporation,Bedford,Massachussetts.1973.
    [2] Bell D E, LaPadula L J. Secure computer system: unified exposition and multics interpretation[R]. Mitre Report,MTR-2997Rev1,1976.
    [3] David Elliott Bell, Looking Back at the Bell-La Padula Model[J], Reston VA,20191,December7,2005.
    [4] Classified National Security Information, Executive Order12958of April17,1995[EB/OL].:http://www.fas.org/sgp/clinton/eo12958.html.
    [5] Amendment To Executive Order12958—Classified National Security Information, Executive Order13142ofNovember19,1999[EB/OL].: http://www.nodis3.gsfc.nasa.gov/displayEO.cfm.
    [6] Further Amendment to Executive Order12958, as Amended, Classified National Security Information,Executive Order13292. March25,2003[EB/OL].: http://www.fas.org/sgp/bush/eoamend.html.
    [7] Classified National Security Information, Executive Order13526of December29,2009[EB/OL].:http://www.nodis3.fsfc.nasa.gov/displayEO.cfm.
    [9] GB17859-1999.计算机信息系统安全保护等级划分准则[S].北京:中国标准出版社,1999.
    [15] GB/T18336.信息技术安全性评估准则[S],北京:中国标准出版社,2001.
    [16] GB/T20273-2006.信息安全技术网络基础安全技术要求[S].北京:中国标准出版社,2006.
    [17] GB/T22240-2008.信息安全技术信息系统安全保护等级定级指南[S].北京:中国标准出版社,2008.
    [18] GB/T25070-2010.信息安全技术信息系统等级保护安全设计技术要求[S].2010.
    [20] Kshemendra N. Paul. Information Sharing Environment[R]. Annual Report to the Congress Prepared by theProgram Manager, Information Sharing Environment, July2010.
    [21] J. M. McConnell. United States Intelligence Community Information Sharing Strategy[R],, OFFICE OF THEDIRECTOR OF NATIONAL INTELLIGENCE, FEBRUARY22,2008.
    [22] Thomas E. McNamara. Information Sharing Environment[R]. Annual Report to the Congress Prepared by theProgram Manager, Information Sharing Environment, July2009.
    [23] Fred H. Cate. Creation of New Information Sharing Steering Committee for the IntelligenceCommunity[R],OFFICE OF THE DIRECTOR OF NATIONAL INTELLIGENCE PUBLIC AFFAIRS OFFICEWASHINGTON, D.C.20511, MARCH6,2007.
    [24] GB/T22239-2008.信息安全技术信息系统安全等级保护基本要求[S].北京:中国标准出版社,2006.
    [25] DoD.8500.2Instruction Information Assurance Implementaion.2003, February6.
    [27] B.Lampson,”Protection,”Proceedings of the Fifth Princeton Symposium of Information Science andSystems,pp.437-443(Mar.1971);reprinted in Operation Syestms Review8(1),pp.18-24(Jan.1974).
    [28] P.Denning,”Third Generation Computer Systems,”Computer Surveys3(4),pp.175-216(Dec.1971).
    [29] G.Graham and P.Denning,”Protection—Pinciples and Practice,”Spring Joint Computer Conference,AFIPSConference Proceedings40,pp.417-429(1972).
    [30] D.Miller and R.Baldwin,”Access Control by Boolean Expression Evaluation,” Proceeding of the5th AnnualComputer Security Applications Conference,pp.131-139(Dec.1990).
    [31] R.Conway, W.Maxwall, and H.Morgan,”On the Implementation of Security Measures in InformationSystems,”Communications of the ACM15(4), pp.211-220(Apr.1972).
    [32] H.Harrison and D.Hsiao,”Full Protection Specifications in the Semantic Model for Database ProtectionLanguages,” Proceedings of the1976ACM Annual Conference, pp.90-95(Oct.1976).
    [33] L.Hoffman,“The Formulary Model for Flexible Privacy and Access Control,” Proceedings of the1971FallJoint Computer Conference, pp.587-601(1971).
    [34] Sandhu R S, Coyne E J, Feinstein H L. Role-based access control models[J]. IEEE Computer,1996,29(2):38-47
    [35] Saddhu R. Rationale for the RBAC96family of access control models[A]. Proceedings of the1st ACMWorkshop on Role-Based Access Control[C]. New York: ACM Press.,1997.
    [36] FERRAIOLODF. KUNN R. Role-Based access contro1[A]. Proceedings of the15th Nation Computer SecurityConference[C], Baltimore,1992,554-563.
    [37] D Denning. A lattice model of secure information flow. Communications of the ACM[J], l976, l9(5):236-243
    [39] REINHOLD V N. Morrie Gasser Building a Secure Computer system[M].1998.
    [40] SANDHU R S. Lattice-based access control models[J]. IEEE Computer,1993,26(11):9-19.
    [41] CAI Y,ZHENG Z R,SHEN C X. A planar attributes model based on multi level security policy[J]. ChineseJournal of Computer,2004,27(5):619-624.
    [42] Ravi S.Sandhu, George,Lattice-Based Access Control Models[J]. IEEE,1993.
    [43] McCullough D.Noninterference and the composition of security properties.In:Proc.of the IEEE Symposiumon Research in Security and Privacy.1988.
    [44] Johnson D,Thayer F.Security and the composition of machines.In:Proc.of the Computer Security FoundationsWorkshop,IEEE Press,1988.14-23
    [45] Goguen J,Meseguer J.Inference control and unwinding.In:Proc.of the IEEE Symposium on Research inSecurity and Privacy,1984.75-86
    [46] Sutherland D.A model of information.In.Proc.of the ninth National Computer Security Conf.1986.175-183.
    [47] Foley S N. A universal theory of information flow. In Proe.ofthe IEEE Symposium on Research in Securityand Privacy.IEEE Press,1987.116-121.
    [48] McLean J.Security models and information flow.In:Proc.of1990IEEE Symposium on Research in Securityand Privacy.IEEE Press.1990.177-186
    [49] O’Halloran C.A calculus of information flow.In:Proc.of FirstEuropean Symposium on Research inComputer Security(SORICS1990),1990.147-159.
    [50] Zakinthinos A.Lee S.A general theory of security properties. In:Proc. of the1997IEEE Symposium onResearch in Se curity and Privacy.IEEE Computer Society Press.1997.94-102.
    [51] Foley S N. A universal theory of information flow. In: Proe. of the IEEE Symposium on Research in Securityand Privacy. IEEE Press,1987.116-121
    [52] Roscoe A W. CSP and determinism in security modeling. In:Proc.of the1995IEEE Symposium onSecurity and Privacy,IEEE Computer Society.1995.114-127.
    [53] Ryan P Y A.A CSP formulation of non—interference and unwinding. Presented at CSFW199O andpublished in Cipher.Winter1990/1991.19-30.
    [54] Ryan P Y A. Mathematical models of computer security. In:Foundations of Security Analysis and Design-Tutorial Lectures(R.Focardi and R.Gorrieri Eds),LNCS,Vol.2171,SpringerVerlag,2001.1-62
    [55] Alien P G.A Comparison of non-Interference and non—Deducibility using CSP、In:Proc.of the FourthIEEE Computer Security Foundations Workshop,Franconia.New Hampshire,June1991.43-54.
    [56] Rosce A W. CSP and determinism in security modeling. In:Proc.of the1995IEEE Symposium on Securityand Privacy,IEEE Computer Society.1995.114-127.
    [57] Roscoe A W.Wood cock J C P.wulf L.Non—interference through Determinism. In:Proc.of EuropeanSymposium on Research in Computer Security1994(ESORICS’94).LNCS,Vo1.875,Springer—Verlag1994.33~53.
    [58] Forster R.NoninteHerence Properties for Nondeterministic Ptocesses:[Vh. D Thesis].Trinity College,University of Oxford.1999.
    [59] Schneider S A.M ay Testing.Non—interference and Compositionality:[-Technical Report CSD-TR-00-022001].Royal Holloway,University of London.
    [60] Focardi R,.Gorrieri R. Classification of security properties(Part I:Information FIow). In:Foundations ofSecurity Analysis andDesign—Tutorial Lectures(R.Focardi and R.Gorrieri Eds). LNCS, Vol.2171,Springer-Verlag,2001,331-396.
    [61] M ilner R.Communicating and M obile Systems.the Pi—Calculus.Cambridge University Press,1999.
    [63] RUSHBY J.Noninterference,Transitivity, and Channel-control Security Policies[R]. Stanford ResearchInstitute, Tech Rep:CSL-92-02,1992.
    [64] HAIGH J T, YONG W D. Extending the noninterference model of MLS for SAT[A]. Proceedings of theSymposium on Securiyt and Privacy[C]. Oakland,CA,l986.232-239.
    [65] Dorothy E.Denning, A Lattice Model of Secure Information Flow[C]. Fifth ACM Symposium on OperatingSystems Principles, The University of Texas at Austin, November19-21,1975.
    [73] Bell D E. Secure computer systems: A network interpretation[A]. Proceedings of the3rd Annual ComputerSecurity Application Conference[C]. Vienna,VA,USA,1987.32-39.
    [74] Lee T M P. Using mandatory integrity to enforce“commercial”security[A]. Proceedings of the8th NationalComputer SecurityConference[C]. Gaithersburg,MD,USA,1985.108-119.
    [76] XIE J,XU F,HUANG H. Trust degree based multilevel security policy and its model of state machine[J].Journal of Software,2004,15(11):1700-1708.
    [77] Varadharajan V, Black S, et al. A Multilevel Security Model for a Distributed Object-Oriented System[C].Computer Security Applications Conference,1990, proceedings of the sixth annual:68-78.
    [78] Roderick Chapman, Adrian Hilton. Enforcing Security and Safety Models with an Information Flow AnalysisTool[C]. SIGAda’04Proceedings of the2004annual ACM SIGAda international conference on Ada: Theengineering.
    [79] Common Criteria. Common Criteria for Information Technology Security Evaluation[S].1999.
    [80] McLean J. Security Models and Information Flow[C]. Research in Security and Privacy.1990.
    [85]刘益和.多密级子网的网络安全信息流模型[J].华东理工大学学报,2007, vol.33增刊:70-73.
    [86] ISO/IEC18028-3.信息技术,安全技术, IT网络安全,第3部分:使用安全网关的网络间的安全通信
    [90] Kapadia A, Al-Muhtadi J, Campbell R, et al.IRBAC2000: secure interoperability using dynamic roletranslation1, UIUCDCS-R-2000-2162[R].University of Illinois,2000.
    [91] Campbell R, Liu Z, Nichnuas D.Seraphism: dynamic interoperable security architecture for active networks[C]//IEEE OPENARCH2000Tel-Aviv, March2000.
    [94] Eric Yong, Jin Tong. Attributed Based Acess Control(ABAC)for Web Seavices. Proe.IEEE InternationalConference on Web Services(ICWS05), Florida, USA, May2005:561—569.
    [95] M.Yague,A.Mana,L.Lopez,etc. Applying the Semantic Web layers to Access Control. Proc.DEXA2003Workshop on Web Semantics. Prague, Czech Republic, September2003:622-626.
    [96] L.Kagal, T.Bemers-Lee, D.Connolly,etc. Using semantic web technologies for open policy management on theweb.21st National Conference on Artificial Intelligence(AAAI),2006.
    [97] A.Uszok,J.M,Bradshaw,etc,Policy and contract management for semantic web services,in:Proceedings ofSemantic Web Se rvices Symposium,Stanford,California,2004.
    [98] T.Priebe,W.Dobmeier, N.Kamprath,Supporting Attribute-Based Access Control with Ontologies.Prc.1stInternational Conference on Availability, Reliability and Security. Vienna,Austria.2006:465—472.
    [100] Apu Kapadia,Jalal A1-Muhtadi,Campbell R,et a1.IRBAC2000:Secure interoperability using dynamicrole translation[C].1st International Conference on Intemet Computing,2000。
    [107] Sandhu R, Park J. Usage Control: A Vision for Next Generation Access Control. MMM-ACNS2003
    [108] Park J. Sandhu R. Originator Control in Usage Control. In3rd International Workshop on Policies forDistributed Systems and Networks(Policy02).2002
    [109] Jaehong Park and Ravi Sandhu, The UCONABC Usage Control Model, ACM Transactions on Informationand System Security,7(1):128-174,2004.
    [115]王铁方,刘晓洁,李涛,龚勋,蒋亚平,杨进,赵奎,胡晓勤.基于家族基因的网格信任模型[J].四川大学学报,2007, Vol.38No.6:123-126.
    [116]张仕斌,刘全,曾鸿.基于开放式网络环境的模糊自主信任模型[J].清华大学学报,2006, Vo l.46, No.S1:1109-1114.
    [121]张景安,郭显娥. P2P网络中基于动态推荐的信任模型[J].计算机工程,2010,(01).
    [122]赵灵犀,田园,邓鲁耀. P2P环境下引入激励机制的动态信任模型[J].计算机应用研究,2010,(01)
    [127] Josang A, Knapskog S J.A metric for trusted systems [J].Global IT Secarity. Wien:Austrian ComputerSociety.1998,541-549.
    [128] Reiter M K,Stubblebine S G.Toward acceptable metrics of authentication[C].Proc.1997IEEE Syrup.Security and Privacy.1997,10-20.
    [129]张京楣,张景祥. P2P网络安全的信任模型研究[J].1001.3695(2003)03-0I6.0:76-77.
    [130]田慧蓉,邹仕洪,王文东,程时端. P2P网络层次化信任模型[J].电子与信息学报.2007, Vol.29No.11:2560-2563.
    [131]贾伟,张国瑜.基于代理机制的交叉认证模型研究[J].计算机应用.2007, Vol.27No.12:2925-2927.