| 摘要: |
| 提出了一种基于一阶逻辑的安全策略管理框架.首先,研究安全策略的语法和语义,给出将安全策略转换成扩展型逻辑程序的算法,进而构造出安全策略基本查询算法;其次,给出将安全策略复杂查询转换成基本查询的算法,进而构造出安全策略验证算法.在良基语义下,上述算法是可终止的、可靠的和完备的,且计算复杂度都是多项式级的.该框架可以在统一的良基语义下实现安全策略表达、语义查询和验证,保证安全策略验证的有效性.此外,该框架不仅兼容现有主流的安全策略语言,还能够管理具有非单调和递归等高级特性的安全策略. |
| 关键词: 安全策略 安全管理 良基语义 策略验证 逻辑编程 |
| DOI:10.3724/SP.J.1001.2012.04023 |
| 分类号: |
| 基金项目:国家自然科学基金(61070186); 国家高技术研究发展计划(863)(2009AA01Z438, 2009AA01Z43); 国家重点基础研究发展计划(973)(2007CB311100) |
|
| Approach of Security Policy Expression and Verification Based on Well-Founded Semantic |
|
BAO Yi-Bao1,2,3, YIN Li-Hua1, FANG Bin-Xing1, GUO Li1
|
|
1.Institute of Computing Technology, The Chinese Academy of Sciences, Beijing 100190, China;2.Institute of Electronic Technology, Information Engineering University of PLA, Zhengzhou 450004, China;3.Graduate University, The Chinese Academy of Sciences, Beijin
|
| Abstract: |
| This study proposes a logic-based security policy framework. First, the study proposes the security policy syntax and semantic. Next, four algoritms are proposed to transfer first-order logic based security policies into extended logic programs to evaluate queries with simple goals, to transfer complex queries into simple ones, and to verify security policies against complex security properties. Under well-founded semantics, all the algorithms are sound and completed, and their computational complexities are polynomial. In this framework, security policy declaration, evaluation and verification are executed under the same semantics, which is significant for security policy management. Furthmore, the framework can manage the security policies with advanced features, such as non-monotony and recursion, which is not supported in many existent security policy management frameworks. |
| Key words: security policy security management well-founded semantic policy verification logic programming |