...
首页> 外文期刊>Science in China >Design of secure operating systems with high security levels
【24h】

Design of secure operating systems with high security levels

机译:具有高安全级别的安全操作系统的设计

获取原文
获取原文并翻译 | 示例
           

摘要

Numerous Internet security incidents have shown that support from secure operating systems is paramount to fighting threats posed by modern computing environments. Based on the requirements of the relevant national and international standards and criteria, in combination with our experience in the design and development of the ANSHENG v4.0 secure operating system with high security level (hereafter simply referred to as ANSHENG OS), this paper addresses the following key issues in the design of secure operating systems with high security levels: security architecture, security policy models, and covert channel analysis. The design principles of security architecture and three basic security models: confidentiality, integrity, and privilege control models are discussed, respectively. Three novel security models and new security architecture are proposed. The prominent features of these proposals, as well as their applications to the ANSHENG OS, are elaborated. Cover channel analysis (CCA) is a well-known hard problem in the design of secure operating systems with high security levels since to date it lacks a sound theoretical basis and systematic analysis approach. In order to resolve the fundamental difficulties of CCA, we have set up a sound theoretical basis for completeness of covert channel identification and have proposed a unified framework for covert channel identification and an efficient backward tracking search method. The successful application of our new proposals to the ANSHENG OS has shown that it can help ease and speedup the entire CCA process.
机译:许多互联网安全事件表明,安全操作系统的支持对于抵御现代计算环境所构成的威胁至关重要。根据相关国家和国际标准和标准的要求,结合我们在设计和开发具有高安全级别的ANSHENG v4.0安全操作系统(以下简称为ANSHENG OS)方面的经验,具有高安全级别的安全操作系统的设计中存在以下关键问题:安全体系结构,安全策略模型和秘密通道分析。安全体系结构的设计原理和三种基本安全模型:机密性,完整性和特权控制模型。提出了三种新颖的安全模型和新的安全体系结构。详细阐述了这些建议的突出功能及其在ANSHENG OS中的应用。覆盖通道分析(CCA)是设计具有高安全级别的安全操作系统中的一个众所周知的难题,因为迄今为止,它缺乏合理的理论基础和系统的分析方法。为了解决CCA的基本难题,我们为隐秘信道识别的完整性建立了良好的理论基础,提出了隐秘信道识别的统一框架和有效的后向搜索方法。我们的新建议在ANSHENG OS中的成功应用表明,它可以帮助简化和加速整个CCA流程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号