标题: 物件资讯与存取权力之流向控制
On Controlling Data and Privilege Flows
作者: 黄干纲
Huang Chien-Kang
谢续平
Shieh Shiuh-Pyng
资讯科学与工程研究所
关键字: 安全;权力;存取控制;强制性存取控制;随意性存取控制;security;privilege;access control;mandatory access control; discretionary access control
公开日期: 1993
摘要: 现有的存取控制模型 (Access Control Model),不论是强制性存取控制
模型 (Mandatory Access Control Model),或是随意性存取控制模型 (
Discretionary Access Control Model) 都无法控制物件内资料 (Data)
的间接接触,或是存取权力 (Privilege) 的间接转移。本篇论文的目的
,在提出一个新的存取控制模型以控制物件的资料和存取权力的直接与间
接流向。 我们使用此模型来定义不同的存取控制策略 (Access Control
Polic y) 以确保物件的资料和存取权力流向的安全。此外,我们提出一
个新的存取控制机制 (Access Control Mechanism) 来强化系统的安全策
略 (Secur ity Policy)。
Neither the mandatory access control model nor the
discretionary access control model can provide the capability
of controlling in direct object data and privilege flows. This
thesis proposes a ne w access control model which is able to
control direct and indire ct object data and privilege flows.
We use this model to define b oth object data and privilege
flows to ensure the security of com puter systems. Furthermore,
we give a new access control mechanis m to enforce the system's
security policies.
URI: http://140.113.39.130/cdrfb3/record/nctu/#NT820392070
http://hdl.handle.net/11536/57879
显示于类别:Thesis