摘要
安全操作系统要能够灵活充分地支持大量广泛的安全策略。这些灵活性需要支持控制访问权限的转移,执行细粒度的访问控制和撤消之前许可的访问权限。当前的一些系统在这些方面有所欠缺。本文介绍了一种操作系统安全构架可以解决当前的这些问题。构架提供了针对每个安全决策必须与安全策略做出协商的转移控制机制,使用保证安全决策一致性的安全决策缓存,并在服务组件中提供了细粒度的访问控制和撤消机制。
Secure 0S need adequate protection mechanisms to flexible support wide range of security policies.The policy flexibilities include controlling migrated access permissions,performing fine grain access control and revoking permitted access permission.But some 0S have shortcomings in these characteristics.The author introduces a flexible security architecture to overcome the limitation of traditional mechanisms.The architecture implemented the mechanisms to control migrated access permissions,to use access decision cache,fine grain control and migrated permission revocation mechanism.
出处
《信息工程大学学报》
2004年第2期143-146,共4页
Journal of Information Engineering University