首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >A trusted subject architecture for multilevel secure object-oriented databases
【24h】

A trusted subject architecture for multilevel secure object-oriented databases

机译:多级安全的面向对象数据库的可信主题体系结构

获取原文
获取原文并翻译 | 示例
           

摘要

We address security in object-oriented database systems for multilevel secure environments. Such an environment consists of users cleared to various security levels, accessing information labeled with varying classifications. Our purpose is three-fold. First, we show how security can be naturally incorporated into the object model of computing so as to form a foundation for building multilevel secure object-oriented database management systems. Next, we show how such an abstract security model can be realized under a cost-effective, viable, and popular security architecture. Finally, we give security arguments based on trusted subjects and a formal proof to demonstrate the confidentiality of our architecture and approach. A notable feature of our solution is the support for secure synchronous write-up operations. This is useful when low level users want to send information to higher level users. In the object-oriented context, this is naturally modeled and efficiently accomplished through write-up messages sent by low level subjects. However, such write-up messages can pose confidentiality leaks (through timing and signaling channels) if the timing of the receipt and processing of the messages is observable to lower level senders. Such covert channels are a formidable obstacle in building high-assurance secure systems. Further, solutions to problems such as these have been known to involve various tradeoffs between confidentiality, integrity, and performance. We present a concurrent computation model that closes such channels while preserving the conflicting goals of confidentiality, integrity, and performance. Finally, we give a confidentiality proof for a trusted subject architecture and implementation and demonstrate that the trusted subject (process) cannot leak information in violation of multilevel security.
机译:我们针对多级安全环境解决面向对象数据库系统中的安全问题。这样的环境由清除为各种安全级别的用户组成,他们访问使用不同分类标记的信息。我们的目的是三方面的。首先,我们展示如何将安全性自然地合并到计算的对象模型中,从而为构建多层安全的面向对象的数据库管理系统奠定基础。接下来,我们展示如何在具有成本效益,可行且流行的安全架构下实现这种抽象安全模型。最后,我们根据可信赖的主题给出安全性论证,并提供正式证明以证明我们的体系结构和方法的机密性。我们解决方案的显着特征是对安全同步写操作的支持。当低级别用户希望将信息发送给高级别用户时,此功能很有用。在面向对象的上下文中,这是自然建模的,可以通过低级主题发送的写消息有效地完成。但是,如果较低级别的发件人可以观察到消息的接收和处理时间,则此类写消息可能会造成机密性泄漏(通过计时和信令通道)。这样的隐蔽通道是构建高安全性安全系统的巨大障碍。此外,已知解决诸如此类问题的方案涉及机密性,完整性和性能之间的各种折衷。我们提出了一个并发计算模型,该模型可以关闭此类通道,同时保留机密性,完整性和性能的冲突目标。最后,我们提供了可信主题体系结构和实现的机密性证明,并证明了可信主题(过程)不会违反多级安全性泄漏信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号