动态信息系统中的解密策略管理

Julien A. Thomas, N. Cuppens-Boulahia, F. Cuppens
{"title":"动态信息系统中的解密策略管理","authors":"Julien A. Thomas, N. Cuppens-Boulahia, F. Cuppens","doi":"10.1109/ARES.2011.30","DOIUrl":null,"url":null,"abstract":"Standard multilevel security (MLS) poli- cies lack flexibility as data classification is consid- ered static. Previous works have addressed this issue and defined declassification requirements, especially in programming languages using a language-based security approach. In this paper, we suggest a dif- ferent approach. We show how to define and enforce declassification policies in databases, seen as sets of logical facts. We first define an information flow con- trol model where data classification may dynamically change. This model combines both confidentiality and integrity requirements to enforce security. We then specify how to enforce declassification policies. Our approach relies on Event-Condition-Action (ECA) rules and provides means to manage the four basic di- mensions of declassification, namely the what?, who?, where? and when? which respectively refer to model- ing information to be declassified, entities responsible for declassification, localization of the declassification and contextual conditions that control declassifica- tion. We formalize and specify our declassification policies and prove it safe and secure with respect to the information flow control model.","PeriodicalId":254443,"journal":{"name":"2011 Sixth International Conference on Availability, Reliability and Security","volume":"19 5","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-08-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Declassification Policy Management in Dynamic Information Systems\",\"authors\":\"Julien A. Thomas, N. Cuppens-Boulahia, F. Cuppens\",\"doi\":\"10.1109/ARES.2011.30\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Standard multilevel security (MLS) poli- cies lack flexibility as data classification is consid- ered static. Previous works have addressed this issue and defined declassification requirements, especially in programming languages using a language-based security approach. In this paper, we suggest a dif- ferent approach. We show how to define and enforce declassification policies in databases, seen as sets of logical facts. We first define an information flow con- trol model where data classification may dynamically change. This model combines both confidentiality and integrity requirements to enforce security. We then specify how to enforce declassification policies. Our approach relies on Event-Condition-Action (ECA) rules and provides means to manage the four basic di- mensions of declassification, namely the what?, who?, where? and when? which respectively refer to model- ing information to be declassified, entities responsible for declassification, localization of the declassification and contextual conditions that control declassifica- tion. We formalize and specify our declassification policies and prove it safe and secure with respect to the information flow control model.\",\"PeriodicalId\":254443,\"journal\":{\"name\":\"2011 Sixth International Conference on Availability, Reliability and Security\",\"volume\":\"19 5\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-08-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2011 Sixth International Conference on Availability, Reliability and Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ARES.2011.30\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 Sixth International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ARES.2011.30","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

由于数据分类被认为是静态的,标准的多层安全策略缺乏灵活性。以前的工作已经解决了这个问题并定义了解密要求,特别是在使用基于语言的安全方法的编程语言中。在本文中,我们提出了一种不同的方法。我们将展示如何在数据库中定义和执行解密策略,将其视为一组逻辑事实。我们首先定义了一个信息流控制模型,其中数据分类可以动态变化。该模型结合了机密性和完整性需求来增强安全性。然后我们指定如何执行解密策略。我们的方法依赖于事件-条件-行动(ECA)规则,并提供了管理解密的四个基本维度的方法,即什么?,谁?,在哪里?当吗?其中分别指待解密的建模信息、负责解密的实体、解密的定位和控制解密的上下文条件。我们形式化并指定我们的解密策略,并证明它在信息流控制模型方面是安全可靠的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Declassification Policy Management in Dynamic Information Systems
Standard multilevel security (MLS) poli- cies lack flexibility as data classification is consid- ered static. Previous works have addressed this issue and defined declassification requirements, especially in programming languages using a language-based security approach. In this paper, we suggest a dif- ferent approach. We show how to define and enforce declassification policies in databases, seen as sets of logical facts. We first define an information flow con- trol model where data classification may dynamically change. This model combines both confidentiality and integrity requirements to enforce security. We then specify how to enforce declassification policies. Our approach relies on Event-Condition-Action (ECA) rules and provides means to manage the four basic di- mensions of declassification, namely the what?, who?, where? and when? which respectively refer to model- ing information to be declassified, entities responsible for declassification, localization of the declassification and contextual conditions that control declassifica- tion. We formalize and specify our declassification policies and prove it safe and secure with respect to the information flow control model.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信