自主访问控制是安全操作系统的基本安全机制之一,传统的文件保护位方式无法满足高安全等级操作系统对于自主访问控制机制的要求。对基于访问控制表的自主访问控制机制的设计和实现进行了研究。在此基础上提出并实现3种重要的增强和改进措施。
Discretionary access control (DAC) is one of the basic security mechanisms of secure operating system. Traditional file permissions can not meet high level secure operating system's requirements to DAC. Design and implementation of DAC mechanism based on ACL is researched. And three important enhancements are proposed and implemented.