Biba模型的严格完整性策略能够保证数据的完整性,但是其静态实施可能降低系统的兼容性.在Biba模型严格完整性策略基础上提出了主体完整性标记动态确定方案.将主体完整性等级扩展为独立的读写区间,根据主体读写历史调整主体可读写的区间,在保护系统完整性的同时提高了系统的兼容性.给出了形式化证明,说明该方案是安全的.指出了现行改进方案中存在的安全隐患及导致该隐患的原因,通过对比分析说明动态确定方案能够消除该安全隐患.
Strict Integrity Policy (SIP) of Biba model can be used to maintain the integrity of data in computer systems, but it might deny some non-malicious access requirements and hence decreases the compatibility of applications. A dynamic determination scheme of subject's integrity level which based on the subject's history behavior is presented, which can increase the compatibility of the software while keeping system integrity as strictly as SIP can. And the proof of it is also given, which shows that the improved SIP is secure. The security risk of the existing improved SIP which is resolved in our scheme is indicated by an example after comparison and analysis, and the main reason which leads to this phenomenon is also demonstrated.