Role-Based Information Flow Control Models
Role-Based Information Flow Control Models
复制标题
基于角色的信息流控制模型
DOI:
10.1109/aina.2014.139
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
M. Takizawa
中科院分区:
文献类型:
--
作者:
Shigenari Nakamura;Dilawaer Duolikun;A. Aikebaier;T. Enokido;M. Takizawa
In information systems, data in an object may illegally flow into another object if a subject manipulates the objects. In this paper, we discuss information flow control models to prevent illegal information to occur in the role-based access control (RBAC) model. First, we define a legal information flow relation ri⇒ rj among roles ri and rj. It means, if a subject granted the role ri manipulates objects before another subject granted the role rj, no illegal information flow occur. We discuss safe systems where no illegal information flow occur even if operations from different subjects are performed in any order. Then, we discuss a role-based synchronization (RBS) protocol and an object-based synchronization (OBS) protocol to prevent illegal information flow in unsafe systems. Here, a transaction is aborted if the transaction reads an object and illegal information flow might occur. In the RBS protocol, the illegal information flow condition is specified in terms of roles while objects in the OBS protocol. We evaluate the RBS and OBS protocols in terms of number of transactions aborted.
影响因子:
5
作者:
Enokido;T;Barolli;V.;and Takizawa;M.
通讯作者:
M.