针对现有的安全域存在许多异构安全数据需要集成的问题,引入多级安全策略(MLs)的思想,提出一种应用扩展权值MLS策略(WEMLS)的安全数据集成模型。定义可信权值的概念,建立进程授权机制和信任计算机制。应用结果表明,该模型能使可信进程更灵活地访问客体。
There exists a variety of heterogeneous data that need to be integrated within a secure domain. In order to solve the issues of the security and integrity of data more flexibly in the process of integration, MultiLevel Security(MLS) is introduced. Although MLS is widely applied in security systems, the application and flexibility in aspects of authentic subject access is poor. An Weight-value-Extended MLS(WEMLS) is proposed. A concept of "authentic weight value" is defined, and authorization mechanisms for processes and the mechanism of calculation of trust value are established, so the authentic processes can access object more flexibly. WEMLS is verified by applying to a security data integration model based on ontology.