摘要
传统的访问控制通过逻辑的方法来防止未授权的信息访问,忽略了物理位置的作用,从而容易遭受地址欺骗类攻击.将位置信息引入访问控制可以提供更好的安全性.在强制访问控制中客体的安全属性与时间密切相关,访问控制模型中应反映客体的安全属性随时间的变化.以经典的Bell-Lapadula模型为基础,提出一个具有时空约束的强制访问控制模型,综合考虑时间和空间约束,在增加访问控制模型灵活性的基础上提高访问控制模型的安全性.
Traditional access control restrains unauthorized access only by logical method,which is vulnerable to suffer from address spoofing because of ignoring physical location.It can provide better security through introducing spatial information into access control.Security properties of objects are closely related to time in mandatory access control model.Therefore,the change of object's security property over time should be reflected in access control model.Based on classic Bell-Lapadula model(BLP),a mandatory access control model with temporal and spatial constraints is proposed,in which both time constraints and space constraints are considered.Compared to BLP model,the new model can provide better flexibility and security.
出处
《北京邮电大学学报》
EI
CAS
CSCD
北大核心
2012年第5期111-114,共4页
Journal of Beijing University of Posts and Telecommunications
基金
北京信息科技大学网络文化与数字传播北京市重点实验室开放课题
信息安全国家重点实验室(中国科学院软件研究所)开放课题
关键词
时空约束
强制访问控制
多级安全
temporal and spatial constraints
mandatory access control
multi-level security