基于安全策略模型的形式化分析对于数据库管理系统达到高安全保障等级的重要性,提出了新的基于PVS的数据库安全策略模型分析方法,该方法结合了PVS函数式语言的特点,通过一系列算法和流程展示了模块化的系统状态、安全属性、操作规则的定义过程.借助PVS定理证明器对BeyonDB数据库管理系统进行安全性分析,结果表明,该方法不但能够提高形式化建模效率,而且可以有效地发现系统设计中存在的漏洞.
The formal analysis of security policy models is very important for DBMS to attain a higher assurance level. A novel formal analysis approach based on PVS for DBMS security polices was proposed. The modular system state, security properties and operation rules were presented by a series of algorithms and processes in our approach, which took advantage of the functional characteristic of PVS language. By analyzing the security of BeyonDB with the PVS theorem prover, it was shown that the approach can improve the efficiency of formal modeling and is effective in discovering system design faults.