• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2006, Vol. 28 ›› Issue (3): 11-13.

• 论文 • 上一篇    下一篇

信息系统安全通过程序设计多方位控制策略的探讨

孟宪虎[1] 陈锐[2]   

  • 出版日期:2006-03-01 发布日期:2010-05-20

  • Online:2006-03-01 Published:2010-05-20

摘要:

信息系统安全需要从多方面予以保障。可是,人们当前在很多情况下是分开考虑的,比如有些主要从数据库方面关注,考虑数据库自身的数据安全、访问控制和数据一致性;而有些着眼于从程序结构、设计方法等来满足系统安全。实际中,用户使用数据库中的数据不是直接从中得到的,而是经过展现在他们面前的程序界面实现的,从用户看到的
 的程序界面到数据库本身的数据,中间可能经过了多个程序控制的环节,而将数据库和程序设计一起考虑,如何提高系统的安全性并不多见。本文探讨了如何通过程序设计对 数据库进行多方位控制来保证信息系统所使用的数据的安全。

关键词: 信息系统 数据库 数据安全 程序设计 多方位控制

Abstract:

The security of information systems needs to be guaranteed from multiple aspects. However, at present, people consider them separately. For example, s ome people focus on the database, such as data security, the access control and data consistency of the database itself; while others concentrate on the program structures, design methods and other aspects to satisfy the needs of system security. Actually, the data used by users is not acquired directly  from the database, but from the visual interface for users. From the visual interface to the data in the database, there may be several program-control  steps, but how to associate the database with the program design to assure the system security is rare. This paper discusses how to control the databas e from multiple aspects through programming, and then guarantee the security of the data used in information systems.

Key words: information system, database, data seeurity, program design, multiple-aspect control