A multilevel file system for high assurance

A multilevel file system for high assurance
复制标题

高保证的多级文件系统

DOI:
10.1109/secpri.1995.398924
复制
发表时间:
1995
期刊:
Proceedings 1995 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
C. Irvine
C. Irvine
中科院分区:
--
文献类型:
--
作者:
C. Irvine

文献摘要

被引文献

相似文献

多级系统的应用程序设计不能仅仅复制那些不可信的世界。当应用程序构建在高保证基础上时,它们将受到底层策略实施机制的约束。必须考虑由不受信任的主体创建和管理多级数据结构。应用程序的设计应该依赖于TCB的安全策略实施服务,而不是在TCB边界之外构建新的访问控制服务。一个通用的文件系统的设计分析的结果,作为一个不受信任的应用程序上的高保证TCB执行。该设计说明了高保证环境所产生的问题的一些解决方案。&lt;<ETX>&gt;
The designs of applications for multilevel systems cannot merely duplicate those of the untrusted world. When applications are built on a high assurance base, they will be constrained by the underlying policy enforcement mechanism. Consideration must be given to the creation and management of multilevel data structures by untrusted subjects. Applications should be designed to rely upon the TCB's security policy enforcement services rather than build new access control services beyond the TCB perimeter. The results of an analysis of the design of a general purpose file system developed to execute as an untrusted application on a high assurance TCB are presented. The design illustrates a number of solutions to problems resulting from a high assurance environment.<<ETX>>