摘要
现有的多级安全系统一般采用BellLaPadula(BLP)模型,但是BLP模型的"向下读,向上写"的访问规则严重影响了系统的可用性、灵活性,破坏了数据完整性。BLP模型也没有对推理进行任何控制。针对上述缺陷,文中采用读写权限分开、多实例、主从结构表和修改读写规则等手段对BLP模型进行改造。改造后的模型不仅增强了系统的机密性而且增强了可用性和数据完整性。
Most of current multilevel secure systems adopted Bell LaPadula(BLP) Model. BLP Models access rules of 'No Read Up,No Write Down' seriously constrain the systems availability and data integrity,it doesnt have any mechanism to control inference. To solve these problems,this paper introduced a method to improve BLP Model by using reading and writing clearance separately,polyinstantiation,masterslaver structure tables and modified reading and writing rules. The extended model presented in this paper not only has more systems confidentiality but also has more availability and data integrity.
出处
《计算机应用》
CSCD
北大核心
2003年第7期103-105,108,共4页
journal of Computer Applications
基金
国家 97 3规划项目 (G1 9990 3 2 70 1 )