摘要
为了提高分布式环境下多级安全实施的正确性和可行性,提出了一个分布式多级安全保护核心架构——分布式可信计算基(DTCB)。DTCB具有三层结构,包括系统层可信计算基、模块层可信计算基和分区层可信计算基,实现了从模块间、分区间到分区内部的逐步细化的信息流和访问控制,有效降低了分布式环境下多级安全实施的复杂性。最后,采用组合无干扰模型形式化证明了DTCB的安全性,结果表明,DTCB能够从整体上为分布式系统提供较好的多级安全保护。
To improve the correctness and feasibility of the implementation of multilevel security in the distributed environment, a distributed multilevel security core architecture -- Distributed Trusted Computing Base (DTCB) was proposed. DTCB was divided into three layers, TCB of System layer, TCB of Module layer and TCB of Partition layer, finer multilevel control granularity was realized step by step, greatly reducing the complexity of the implementation of multilevel security in the distributed environment. At last, based on the eomposable noninterference model, the security of DTCB was formally proved. The result shows that DTCB assures the multilevel security of distributed system as a whole.
出处
《计算机应用》
CSCD
北大核心
2013年第3期712-716,共5页
journal of Computer Applications
基金
国家973计划项目(2011CB311801)
国家863计划项目(2012AA012704)
河南省科技创新人才计划项目(114200510001)
关键词
多级安全
无干扰
可信计算基
分布式系统
架构
muhilevel security
noninterference
Trusted Computing Base (TCB)
distributed system
architecture