[1]李海华.一种基于信息流控制的多级安全通道模型[J].计算机技术与发展,2023,33(03):85-92.[doi:10. 3969 / j. issn. 1673-629X. 2023. 03. 013]
 LI Hai-hua.A Multi-level Secure Channel Model Based on Information Flow Control[J].,2023,33(03):85-92.[doi:10. 3969 / j. issn. 1673-629X. 2023. 03. 013]
点击复制

一种基于信息流控制的多级安全通道模型()

《计算机技术与发展》[ISSN:1006-6977/CN:61-1281/TN]

卷:
33
期数:
2023年03期
页码:
85-92
栏目:
网络空间安全
出版日期:
2023-03-10

文章信息/Info

Title:
A Multi-level Secure Channel Model Based on Information Flow Control
文章编号:
1673-629X(2023)03-0085-08
作者:
李海华12
1. 中国人民解放军战略支援部队信息工程大学,河南 郑州 450002;
2. 河南工业贸易职业学院,河南 郑州 450012
Author(s):
LI Hai-hua12
1. Information Engineering University,Zhengzhou 450002,China;
2. Henan Industry and Trade Vocational College,Zhengzhou 450012,China
关键词:
信息流安全通道安全系统操作集操作规则
Keywords:
information flowsecure channelsecurity systemaction setsoperating rules
分类号:
TP393. 2
DOI:
10. 3969 / j. issn. 1673-629X. 2023. 03. 013
摘要:
针对安全通信及多级安全访问控制应对网络通信数据等级保护这两种模型存在的缺陷,明确了安全通道、实体、安全客体、系统状态、安全系统等几个概念,定义了由创建、打开、读、写、关闭等构成的操作集,给出了安全通道操作、安全通道处理约束、安全标记调整等模型安全规则构成的安全通道操作规则集合,保证了通道操作、安全标记调整、信息流控制的可靠及安全,构建了一种基于安全标记的网络安全通信模型。 对模型定理作了进一步的证明,提出一个模型实例,并与相关模型进行了性能对比,该模型具有通用性、灵活性等特点,实现了多级网络环境下不同密级信息流的隔离保护与安全传输。
Abstract:
Aiming at the defects of the two models of secure communication and multi-level secure access control dealing with thehierarchical protection of network communication data,we define several concepts,such as secure channel,entity,security object,systemstate and security system,and define the operation set composed of creation, opening,reading,writing and closing. Present a set of safechannel operation rules composed of safe channel operation, safe channel processing constraints, safe tag adjustment and other modelsafety rules to ensure the reliability and security of channel operation,safe tag adjustment and information flow control,and construct asafe network communication model based on security tag. The model theorem is further proved,a model example is presented,and theperformance of the model is compared with that of the relevant model. The model has the characteristics of universality and flexibility,and realizes the isolation protection and secure transmission of different secret levels of information flow in multilevel network environment.
更新日期/Last Update: 2023-03-10