A formal model for integrity protection based on DTE technique

被引:1
作者
Qingguang Ji
Sihan Qing
Yeping He
机构
[1] Chinese Academy of Sciences,Engineering Research Center for Information Security Technology, Institute of Software
[2] Chinese Academy of Sciences,Infrastructure Software Engineering Center, Institute of Software
来源
Science in China Series F: Information Sciences | 2006年 / 49卷
关键词
formal model; integrity policy; information flow; domain; type;
D O I
暂无
中图分类号
学科分类号
摘要
In order to provide integrity protection for the secure operating system to satisfy the structured protection class’ requirements, a DTE technique based integrity protection formalization model is proposed after the implications and structures of the integrity policy have been analyzed in detail. This model consists of some basic rules for configuring DTE and a state transition model, which are used to instruct how the domains and types are set, and how security invariants obtained from initial configuration are maintained in the process of system transition respectively. In this model, ten invariants are introduced, especially, some new invariants dealing with information flow are proposed, and their relations with corresponding invariants described in literatures are also discussed. The thirteen transition rules with well-formed atomicity are presented in a well-operational manner. The basic security theorems correspond to these invariants and transition rules are proved. The rationalities for proposing the invariants are further annotated via analyzing the differences between this model and ones described in literatures. At last but not least, future works are prospected, especially, it is pointed out that it is possible to use this model to analyze SE-Linux security.
引用
收藏
页码:545 / 565
页数:20
相关论文
共 4 条
[1]  
Abrams M. D.(1995)Trusted system concepts Computers and Security 14 45-56
[2]  
Joyce M. V.(2001)Practical safety in flexible access control models ACM Transactions on Information and System Security 4 158-190
[3]  
Jaeger T.(undefined)undefined undefined undefined undefined-undefined
[4]  
Tidswell J. E.(undefined)undefined undefined undefined undefined-undefined