根据信息系统的主客体访问属性规律,给出了一种可行的BLP模型密级赋值方法,提出了2个归并条件。继而给出了归并后的BLP模型下的主客体密级赋值的数学模型。证明了当条件解是非常值赋值解时,其扩张还原解不一定是全局解的结果,但由该解可以得到全局解的近似条件修改赋值解。利用近似条件修改赋值解,给出了某国家级信息系统BLP模型的密级具体赋值,解决了应用中的实际困难问题。
According to the access attribute properties between subjects and objects in the information system, a viable method of the BLP model secret level valuation was given, and two merging conditions were put forward. The mathe-matical model of subject-object secret level valuation under BLP model was established on the two merging conditions. When the condition solution was not the constant one, its expansion solution being not sure the global one was proved, but the approximate condition modification valuation solution could be obtained from it. Using the above results, one dif-ficult problem from one national information system about the BLP model secret level valuation was solved.