摘要
系统运行时受环境和各种外界因素影响,加之内部多实体间信息流相互干扰,可能会破坏系统的可信性,最终导致产生非预期输出。现有研究主要针对初始化可信硬件环境下实体的完整性度量,未能考虑机密性带来的可信影响,同时对于实体可信度量的频率未能与实体推进时机同步。基于此提出一种基于信息流传递理论的多级动态可信度量模型,该模型以信息流的非传递无干扰理论为依据,通过引入可信代理模块,设计一种多级安全访问控制策略,分别从实体完整性和机密性两方面对系统中实体进行动态可信性度量。最后给出该模型的形式化描述和可信证明,结合抽象系统实例来说明该模型的有效性,相比现有研究,所提模型具有更好的度量实时性,是一种上下文感知的细粒度可信度量模型。
System runtime environment and multiple external factors together with internal multi-entity information flow mutual interference can break system credibility,and result in unexpected outputs.Existing research mainly aims at the integrity measurement of entities under the initialized trusted hardware environment,failing to consider the trusted influence brought by the confidentiality,and the frequency of the trusted measurement of entities cannot be synchronized with the progress.We propose a multilevel dynamic trusted measurement model based on information flow theory.By using the basic idea of intransitive noninterference theory of information flow as reference and introducing a trusted proxy module,we design a multilevel security access control policy,hence the trusted measurement of entities can be measured dynamically from aspects of entity integrity and confidentiality.We describe the formal description and trusted proof of the model and verify the model through an abstract system example.Compared with existing research,it has a better real-time measurement performance,and it is a context-aware fine-grain trusted measurement model.
作者
迮恺
陈丹
庄毅
ZE Kai;CHEN Dan;ZHUANG Yi(College of Computer Science and Technology,Nanjing University of Aeronautics and Astronautics,Nanjing 211106;Collaborative Innovation Center for Novel Software and Industrialization,Nanjing 211106,China)
出处
《计算机工程与科学》
CSCD
北大核心
2018年第12期2156-2163,共8页
Computer Engineering & Science
基金
国家自然科学基金(61572253)
"十三五"装备预研领域基金(61402420101HK02001)
航空科学基金(2016ZC52030)
关键词
可信度量
信息流
非传递无干扰
访问控制
形式化描述
trusted measurement
information flow
intransitive noninterference
access control
formal description
作者简介
迮恺(1993),男,安徽铜陵人,硕士生,CCF会员(54528G),研究方向为可信计算和形式化方法。E-mail:ZeKai@nuaa.edu.cn;陈丹(1976),女,陕西西安人,博士,副教授,研究方向为网络安全和信息隐藏。E-mail:chendan@nuaa.edu.cn;庄毅(1956),女,江苏淮安人,博士,教授,研究方向为网络安全和可信计算。E-mail:zhuangyi@nuaa.edu.cn