首页> 外文会议>Computer Safety, Reliability, and Security >A Context-Aware Mandatory Access Control Model for Multilevel Security Environments
【24h】

A Context-Aware Mandatory Access Control Model for Multilevel Security Environments

机译:多级安全环境的上下文感知强制访问控制模型

获取原文
获取原文并翻译 | 示例

摘要

Mandatory access control models have traditionally been employed as a robust security mechanism in multilevel security environments like military domains. In traditional mandatory models, the security classes associated with entities are context-insensitive. However, context-sensitivity of security classes may be required in some environments. Moreover, as computing technology becomes more pervasive, flexible access control mechanisms are needed. Unlike traditional approaches for access control, such access decisions depend on the combination of the required credentials of users and the context of the system. Incorporating context-awareness into mandatory access control models results in a model appropriate for handling such context-aware policies and context-sensitive class association mostly needed in multilevel security environments. In this paper, we introduce a context-aware mandatory access control model (CAMAC) capable of dynamic adaptation of access control policies to the context, and handling context-sensitive class association, in addition to preservation of confidentiality and integrity. One of the most significant characteristics of the model is its high expressiveness which allows us to express various mandatory access control models such as Bell-LaPadula, Biba, Dion, and Chinese Wall with it.
机译:传统上,强制访问控制模型已被用作军事领域等多层安全环境中的鲁棒安全机制。在传统的强制性模型中,与实体关联的安全类是上下文无关的。但是,在某些环境中可能需要安全级别的上下文相关性。此外,随着计算技术的普及,需要灵活的访问控制机制。与传统的访问控制方法不同,此类访问决策取决于所需的用户凭据和系统上下文的组合。将上下文感知合并到强制访问控制模型中,将得到一个适合于处理此类上下文感知策略和上下文敏感类关联的模型,该策略是多级安全环境中最需要的。在本文中,我们介绍了一种上下文感知的强制访问控制模型(CAMAC),该模型能够动态地对上下文进行访问控制策略的适应,并能在保持机密性和完整性的基础上处理上下文敏感的类关联。该模型最重要的特征之一就是它的高表达能力,它使我们能够用它来表达各种强制性的访问控制模型,例如Bell-LaPadula,Biba,Dion和Chinese Wall。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号