| 摘要: |
| 讨论了在基于角色的安全系统中实现强制访问控制(mandatory access control,简称MAC)的 问题.首先介绍了角色的基本概念及其在安全系统中的应用和MAC的基本概念,然后给出了一 个利用角色机制实现强制访问控制的方法,通过将每个角色上下文处理为独立的安全级并施 行非循环信息流要求,实现了强制访问控制. |
| 关键词: 安全级,信息流,强制访问控制,角色,基于角色的 安全机制. |
| DOI: |
| 分类号: |
| 基金项目:本文研究得到重庆市资助科技项目基金(No.99-5517)资助. |
|
| Realizing Mandatory Access Control in Role-Based Security System |
|
LI Li-xin,CHEN Wei-min,HUANG Shang-lian
|
| Abstract: |
| The realization of MAC (mandatory access control) in role-based protection syst em is discussed. First, the definition of role and the application in security a re discussed. Then the concept of MAC is introduced and a scheme of role-based protection which realizes MAC is developed, by viewing each of the role contexts as an independent security-level and imposing non-cyclic information flow req uirement. |
| Key words: Security level, information flow, MAC (mandatory access control), role, role-ba sed security mechanism. |