• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学

• 计算机网络与信息安全 • 上一篇    下一篇

基于信息流的多级动态可信度量模型

迮恺1,陈丹1,2,庄毅1   

  1. (1.南京航空航天大学计算机科学与技术学院,江苏 南京 211106;
    2.软件新技术与产业化协同创新中心,江苏 南京 211106)
     
  • 收稿日期:2017-09-07 修回日期:2018-02-14 出版日期:2018-12-25 发布日期:2018-12-25
  • 基金资助:

    国家自然科学基金(61572253);“十三五”装备预研领域基金(61402420101HK02001);航空科学基金(2016ZC52030)

A multilevel dynamic trusted measurement
model based on information flow

ZE Kai1,CHEN Dan1,2,ZHUANG Yi1   

  1. (1.College of Computer Science and Technology,Nanjing University of Aeronautics and Astronautics,Nanjing 211106;
    2.Collaborative Innovation Center for Novel Software and Industrialization,Nanjing 211106,China)
     
  • Received:2017-09-07 Revised:2018-02-14 Online:2018-12-25 Published:2018-12-25

摘要:

系统运行时受环境和各种外界因素影响,加之内部多实体间信息流相互干扰,可能会破坏系统的可信性,最终导致产生非预期输出。现有研究主要针对初始化可信硬件环境下实体的完整性度量,未能考虑机密性带来的可信影响,同时对于实体可信度量的频率未能与实体推进时机同步。基于此提出一种基于信息流传递理论的多级动态可信度量模型,该模型以信息流的非传递无干扰理论为依据,通过引入可信代理模块,设计一种多级安全访问控制策略,分别从实体完整性和机密性两方面对系统中实体进行动态可信性度量。最后给出该模型的形式化描述和可信证明,结合抽象系统实例来说明该模型的有效性,相比现有研究,所提模型具有更好的度量实时性,是一种上下文感知的细粒度可信度量模型。

 

关键词: 可信度量, 信息流, 非传递无干扰, 访问控制, 形式化描述

Abstract:

System runtime environment and multiple external factors together with internal multientity information flow mutual interference can break system credibility, and result in unexpected outputs. Existing research mainly aims at the integrity measurement of entities under the initialized trusted hardware environment, failing to consider the trusted influence brought by the confidentiality, and the frequency of the trusted measurement of entities cannot be synchronized with the progress. We propose a multilevel dynamic trusted measurement model based on information flow theory. By using the basic idea of intransitive noninterference theory of information flow as reference and introducing a trusted proxy module, we design a multilevel security access control policy, hence the trusted measurement of entities can be measured dynamically from aspects of entity integrity and confidentiality. We describe the formal description and trusted proof of the model and verify the model through an abstract system example. Compared with existing research, it has a better realtime measurement performance, and it is a contextaware fine-grain trusted measurement model.
 

Key words: trusted measurement, information flow, intransitive noninterference, access control, formal description