首页> 外国专利> METHOD AND APPARATUS FOR VERIFICATION OF INFORMATION ACCESS IN ICT SYSTEMS HAVING MULTIPLE SECURITY DIMENSIONS AND MULTIPLE SECURITY LEVELS

METHOD AND APPARATUS FOR VERIFICATION OF INFORMATION ACCESS IN ICT SYSTEMS HAVING MULTIPLE SECURITY DIMENSIONS AND MULTIPLE SECURITY LEVELS

机译:验证具有多个安全维度和多个安全级别的ICT系统中的信息访问权限的方法和装置

摘要

We describe a model for multilevel information security. Information security is defined as combinations of confidentiality, integrity and availability. These three aspects are regarded as properties of a generic information object, and are treated as mutually independent. Each aspect is represented by an axis in an n-dimensional vector space, where n is the number of independent security aspects of interest. The model can ensure directed information flow along an arbitrary number of axes simultaneously. An information object is assigned a security label denoting the security level along an arbitrary number of axes. The model is role based. A role is assigned an access label along the same axes. Verification of a role's access to information is performed by comparing access label with security label. Since the aspects represented by each axis are mutually independent, each axis may be treated by itself. This enables a very efficient algorithm for verification of access. The model will therefore be suited for systems having low processing capacity. Based on this model, we describe a method and an apparatus to ensure confidentiality, integrity and availability for information from peripheral equipment in communications networks. Such peripheral equipment may be, but is not limited to personal terminals for rescue personnel, soldiers etc, sensors (detectors) for smoke, gases, motion, intrusion etc. The invention supports decision support systems in that the information has known confidentiality, integrity and availability even from inexpensive sensors, which do not include a processor or the like. The invention differs from prior art in that it, among other features: —Treats an arbitrary number of mutually independent aspects of information security, —Assumes that confidentiality, integrity and availability are mutually independent variables, —On this basis can verify access to information by means of simple binary operations, by a simple logic gate circuit or by a processor.
机译:我们描述了一种用于多级信息安全的模型。信息安全性定义为机密性,完整性和可用性的组合。这三个方面被视为通用信息对象的属性,并且被视为相互独立。每个方面都由n维向量空间中的一个轴表示,其中n是感兴趣的独立安全方面的数量。该模型可以确保定向信息同时沿任意数量的轴流动。为信息对象分配了一个安全标签,该标签表示沿任意数量的轴的安全级别。该模型基于角色。沿相同的轴为角色分配了访问标签。通过比较访问标签和安全标签来验证角色对信息的访问。由于每个轴表示的方面是相互独立的,因此每个轴可以自己处理。这实现了用于访问验证的非常有效的算法。因此,该模型将适用于处理能力低的系统。基于该模型,我们描述了一种确保通信网络中来自外围设备的信息的机密性,完整性和可用性的方法和装置。这种外围设备可以是但不限于救援人员,士兵等的个人终端,烟雾,气体,运动,入侵等的传感器(检测器)。本发明支持决策支持系统,因为该信息具有已知的机密性,完整性和完整性。甚至可以从不包含处理器等的廉价传感器获得可用性。本发明与现有技术的不同之处在于,它具有以下特点:-处理信息安全的任意数量的相互独立的方面,-假定机密性,完整性和可用性是相互独立的变量,-在此基础上可以通过以下方式验证对信息的访问通过简单的逻辑门电路或处理器进行的简单二进制操作的方法。

著录项

  • 公开/公告号US2010049974A1

    专利类型

  • 公开/公告日2010-02-25

    原文格式PDF

  • 申请/专利权人 ELI WINJUM;BJORN KJETIL MOLMANN;

    申请/专利号US20080595509

  • 发明设计人 BJORN KJETIL MOLMANN;ELI WINJUM;

    申请日2008-04-15

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 18:51:45

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号