首页> 外国专利> VIRTUAL ACCESS CONTROL SECURITY SYSTEM FOR SUPPORTING VARIOUS ACCESS CONTROL POLICIES IN OPERATING SYSTEM OR APPLICATION

VIRTUAL ACCESS CONTROL SECURITY SYSTEM FOR SUPPORTING VARIOUS ACCESS CONTROL POLICIES IN OPERATING SYSTEM OR APPLICATION

机译:支持访问系统或应用程序中各种访问控制策略的虚拟访问控制安全系统

摘要

The present invention relates to a virtual access control security system and a security method using a virtual access control system to provide various access control policies in the operating system or applications.;To this end, the virtual access control security system of the present invention requests whether the subject permits an action to be performed on an object to which the subject wants to access, and requests and enforces a policy to execute the action on the object according to the permission result of the request. module; Virtual access control that can be applied dynamically to the operating system by implementing policy decision module that decides whether to grant access to the request using the set access permission information and various access control policies such as MAC, DAC, RBAC etc. System module; Record the information on the subject's request for the action that is not allowed to access the object, and determine the abnormal behavior by analyzing the abnormal behavior for the subject that is allowed to access the object and recall the subject. Includes a policy control module that controls access to an object.;According to the present invention, as a new access control security structure using a virtual access control system is provided, various access control policies can be easily applied to an operating system, and the structure is simple, so that the design and implementation is easy, and a new access control model is provided. Can be easily applied.; Security, access control, policy request and execution, policy decision, policy control, subject, object, action, virtual access control system, virtual access control security system, security method
机译:本发明涉及一种虚拟访问控制安全系统和使用该虚拟访问控制系统在操作系统或应用程序中提供各种访问控制策略的安全方法。为此,本发明的虚拟访问控制安全系统要求对象是否允许对对象要访问的对象执行操作,并根据请求的允许结果请求并强制执行对对象执行操作的策略。模块虚拟访问控制,可以通过实现策略决策模块来动态应用于操作系统,该策略决策模块使用设置的访问许可信息和各种访问控制策略(例如MAC,DAC,RBAC等)来决定是否授予对请求的访问。记录关于对象的不允许访问对象的操作请求的信息,并通过分析允许访问对象的对象的异常行为并调用对象来确定异常行为。包括策略控制模块,该策略控制模块控制对对象的访问。根据本发明,由于提供了使用虚拟访问控制系统的新访问控制安全性结构,因此各种访问控制策略可以轻松地应用于操作系统,并且结构简单,设计和实现容易,并提供了一种新的访问控制模型。可以很容易地应用。安全性,访问控制,策略请求和执行,策略决策,策略控制,主题,对象,操作,虚拟访问控制系统,虚拟访问控制安全系统,安全方法

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号