Access Flow: A Protection Model which Integrates Access Control and Information Flow

Access Flow: A Protection Model which Integrates Access Control and Information Flow
复制标题

访问流:一种集成访问控制和信息流的保护模型

DOI:
10.1109/sp.1981.10004
复制
发表时间:
1981
期刊:
1981 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Alley Stoughton
Alley Stoughton
中科院分区:
--
文献类型:
--
作者:
Alley Stoughton

文献摘要

被引文献

相似文献

过去关于操作系统保护的工作集中在两个概念上:访问控制和信息流。基于访问控制或保护矩阵的保护系统控制用户可以操纵对象的方式。信息流或基于安全等级的系统控制用户之间的信息流。虽然已经指出,这两个概念是必不可少的真实的保护制度,以前的工作没有比较这两个概念,或制定一个保护模式,将这些概念。本文对访问控制和信息流进行了比较和对比,并支持这两种通知对于真实的保护系统都是必不可少的这一论断。指出了军事信息流分类模型对现实建模能力差的问题,提出了一种新的基于受控秘密共享的信息流模型。一个保护模型,集成了访问控制和信息流,然后开发和形式化定义,并描述了这个模型的一些示例应用。
Past work concerning operating system protection has focused on two notions: access control and information flow. Access control or protection matrix based protection systems control the ways in which users may manipulate objects. Information flow or security class based systems control the flow of information between users. Although it has been noted that both notions are essential to real protection systems, no previous work has compared the two notions, or developed a protection model that integrates those notions. This paper compares and contrasts access control and information flow and supports the assertion that both notious are essential to real protection systems. It is argued that the military classification model of information flow poorly models reality, and a new information flow model based on the controlled sharing of secrets is introduced. A protection model that integrates access control and information flow is then developed and formally defined, and some example applications of this model are described.