首页> 外文会议>Software engineering and formal methods >A Complete Generative Label Model for Lattice-Based Access Control Models
【24h】

A Complete Generative Label Model for Lattice-Based Access Control Models

机译:基于格的访问控制模型的完整的生成标签模型

获取原文
获取原文并翻译 | 示例

摘要

Lattice-based access control models (LBAC) initiated by Bell-LaPadula (BLP)/Biba models, and consolidated by Denning have played a vital role in building secure systems via Information Flow Control (IFC). IFC systems typically label data and track labels, while allowing users to exercise appropriate access privileges. This is defined through a finite set of security classes over a lattice. Recently, IFC has also been playing a crucial role in formally establishing the security of operating systems/programs. Towards such a goal, researchers often use assertions to keep track of the flow of information from one subject/object to another object/subject. Specifying and realizing these assertions will be greatly benefitted, if the underlying labels of objects/subjects can be interpreted in terms of access permissions/rights of subjects/objects as well as subjects/objects that have influenced them; these would lead to automatic generation of proof obligations/assertions. Thus, if one can arrive at a label model for LBAC that satisfies properties like (i) intuitive and expressive labels, (ii) completeness w.r.t. Denning's lattice model, and (iii) efficient computations on labels, then building/certifying secure systems using LBAC will be greatly benefitted. In this paper, we arrive at such a semantic generative model (that tracks readers/writers of objects/subjects) for the Denning's lattice model, and establish a strong correspondence between syntactic label policies and semantically labelled policies. Such a correspondence leads to the derivation of the recently proposed Readers-Writers Flow Model (RWFM). It may be noted that RWFM [11] also deals with declassification rules which is not discussed here as it is not relevant here. The relationship, further establishes that the RWFM label model provides an application-independent concrete generative label model that is sound and complete wrt Denning's Model. We define the semantics of information flow in this label model, and argue that reading and writing induce possibly different pre-orders on the set of subjects. Hence, the subject relations become explicit, making it possible to derive relations from the labels. We further define a notion of information dominance on subjects and show that the notion of principal hierarchy can be naturally defined that is consistent with the IFC model; this perhaps overcomes the adverse impact on the flow policy that is often experienced during the classical approach of defining the hierarchy orthogonally. This enables us to realize Role-Based Access Control (RBAC) structurally and enforce information flow security. Further, we demonstrate how the underlying label model succinctly subsumes various lattice-based control models like BLP, Biba, RBAC, Chinese wall model, etc. MAC; DAC; LBAC; RBAC; Chinese wall
机译:由Bell-LaPadula(BLP)/ Biba模型发起并由Denning合并的基于格的访问控制模型(LBAC)在通过信息流控制(IFC)构建安全系统中发挥了至关重要的作用。 IFC系统通常为数据加标签并跟踪标签,同时允许用户行使适当的访问权限。这是通过网格上有限的一组安全类定义的。最近,IFC在正式建立操作系统/程序的安全性方面也起着至关重要的作用。为了实现这一目标,研究人员经常使用断言来跟踪从一个对象/对象到另一对象/对象的信息流。如果可以根据对象/对象以及影响对象的对象的访问权限/权限来解释对象/对象的基本标签,那么指定和实现这些断言将大为受益。这些将导致自动生成证明义务/断言。因此,如果可以找到满足(i)直观和富有表现力的标签之类的属性的LBAC标签模型,(ii)完整性。 Denning的晶格模型,以及(iii)在标签上进行高效计算,然后使用LBAC构建/验证安全系统将大为受益。在本文中,我们为Denning的格模型建立了一个语义生成模型(跟踪对象/对象的读/写),并在句法标记策略和语义标记策略之间建立了强烈的对应关系。这样的对应导致了最近提出的读者-作家流模型(RWFM)的推导。可能需要注意的是,RWFM [11]也处理解密规则,此处不讨论,因为此处不相关。这种关系进一步确定了RWFM标签模型提供了与应用程序无关的具体的生成标签模型,该模型可靠且完整,具有Denning模型。我们在此标签模型中定义了信息流的语义,并认为阅读和写作在主题集上可能会导致不同的前置。因此,主题关系变得明确,从而有可能从标签中得出关系。我们进一步定义了主题上的信息优势的概念,并表明可以自然地定义与IFC模型相一致的主体层次概念。这也许可以克服在正交定义层次结构的经典方法中经常遇到的对流量策略的不利影响。这使我们能够在结构上实现基于角色的访问控制(RBAC)并加强信息流的安全性。此外,我们演示了基础标签模型如何简洁地包含各种基于格子的控制模型,例如BLP,Biba,RBAC,中国墙模型等。 DAC; LBAC; RBAC;中国墙

著录项

  • 来源
  • 会议地点 Trento(IT);Vienna(AU)
  • 作者单位

    Department of Computer Science and Engineering, Indian Institute of Technology Bombay, Mumbai 400076, India;

    Department of Computer Science and Engineering, Indian Institute of Technology Bombay, Mumbai 400076, India;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号