Scalable Large-Scale Precise System-Wide Data-Driven Usage Control Across Layers of Abstraction and Across Machines
Scalable Large-Scale Precise System-Wide Data-Driven Usage Control Across Layers of Abstraction and Across Machines
批准号:
183688753
负责人:
Professor Dr. Alexander Pretschner
金额:
$0.0万
依托单位国家:
德国
项目类别:
Priority Programmes
财政年份:
2010
资助国家:
德国
项目状态:
已结题
起止时间:
2009-12-31 至 2015-12-31
中文摘要
使用控制要求规定了访问数据后对数据使用的限制(“三天内删除”、“不复制”)。然而,在分布式环境中,一旦数据泄露,通常就失去了对数据的控制。该项目的目标是在运行时强制执行,或者至少检测违反这类属性的行为。现有的方法集中在一个具体的数据表示上,例如,一个文件。在这个项目中,寻求一个独立于表示的解决方案。为此目的,参考监视器的现有概念- -通常是为技术事件定义的- -将首先通过数据流检测加以扩展:对文件的删除要求也将适用于该文件的所有副本,因此必须跟踪该文件的存在。其次,将提供一个框架,用于在不同抽象层次上定义精确的技术机器级语义:“复制”意味着复制文件,在Excel中复制和粘贴,以及发送电子邮件。第三,为了执行数据驱动的使用控制策略,在不同的抽象级别(例如,操作系统、运行时系统、窗口系统、独立的IT系统)上定义了引用监视器。数据流不仅在这些级别上被监控,而且在这些级别之间也被监控。例如,在禁止“复制”的严格解释下,如果想要最终禁止复制和粘贴,则必须跟踪数据从文件通过操作系统通过Java VM到本机显示功能的路径
英文摘要
Usage control requirements stipulate constraints on the usage of data after access to them (“de-lete within three days,” “don’t copy.“) Control over data is, however, usually lost in distributed settings once the data is given away.The goal of the project is the run-time enforcement or at least the detection of violation of this kind of properties. Existing approaches focus on one concrete data representation, e.g., a file. In this project, a representation-independent solution is sought. To this end, existing concepts for reference monitors – that are usually defined for technical events – will, firstly, be extended by data flow detection: A deletion requirement for a file will then pertain to all copies of that file as well, the existence of which must hence be tracked. Secondly, a framework for the definition of precise technical machine-level semantics at different levels of abstraction will be provided: “copy” means, among other things, copy a file, copy&paste in Excel, and sending an email. To enforce data-driven usage control policies, reference monitors are, thirdly, defined at different levels of abstraction (e.g., operating system, runtime system, windowing system, separate IT system). Data flows will not only be monitored at each of these levels, but also in-between lev-els. For instance, under a strict interpretation of a prohibition to “copy,” the data’s path from a file through the operating system through the Java VM to native display functions must be tracked if one wants to, finally, prohibit copy&paste
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
基于水稻穗粒数关键基因LARGE2提高作物产量的探索与应用
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2026
-
负责人:黄洛将
-
依托单位:
水稻穗粒数调控关键因子LARGE6的分子遗传网络解析
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:黄洛将
-
依托单位:
量子自旋液体中拓扑拟粒子的性质:量子蒙特卡罗和新的large-N理论
-
批准号:12074246
-
项目类别:面上项目
-
资助金额:62.0万元
-
批准年份:2020
-
负责人:Yoshitomo Kamiya
-
依托单位:
甘蓝型油菜Large Grain基因调控粒重的分子机制研究
-
批准号:31972875
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:石江华
-
依托单位:
Large PB/PB小鼠 视网膜新生血管模型的研究
-
批准号:30971650
-
项目类别:面上项目
-
资助金额:8.0万元
-
批准年份:2009
-
负责人:周旻
-
依托单位:
基因discs large在果蝇卵母细胞的后端定位及其体轴极性形成中的作用机制
-
批准号:30800648
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2008
-
负责人:于玲珠
-
依托单位:
LARGE基因对口腔癌细胞中α-DG糖基化及表达的分子调控
-
批准号:30772435
-
项目类别:面上项目
-
资助金额:29.0万元
-
批准年份:2007
-
负责人:尚政军
-
依托单位: