首页> 外文期刊>International Journal of Information Security >Controlled query evaluation for enforcing confidentiality in complete information systems
【24h】

Controlled query evaluation for enforcing confidentiality in complete information systems

机译:受控查询评估,用于在完整信息系统中加强机密性

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

An important goal of security in information systems is confidentiality. A confidentiality policy specifies which users should be forbidden to acquire what kind of information. A controlled query evaluation should enforce such a policy even if users are able to reason about a priori knowledge and the answers to previous queries. The following aspects are considered: formal models of confidentiality policies based on potential secrets or secrecies, user awareness of the policy instance, and enforcement methods applying either lying or refusal, or a combination thereof. Reconsidering previous work and filling the gaps, we comprehensively treat and compare the resulting 12 cases. Thereby, the assumed completeness of the information system is essentially used.
机译:信息系统安全性的重要目标是机密性。保密策略指定应禁止哪些用户获取什么样的信息。即使用户能够推理出先验知识和对先前查询的回答,受控查询评估也应实施此类策略。考虑以下方面:基于潜在秘密或保密性的保密策略的正式模型,用户对策略实例的意识以及应用说谎或拒绝的执法方法,或其组合。在重新考虑先前的工作并填补空白之前,我们对得到的12例病例进行了综合治疗和比较。因此,基本上使用了信息系统的假定完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号