强制访问控制是建设高级别安全信息系统的必要条件.本文基于Biba模型,重点给出了信息系统中系统管理员、安全管理员和安全审计员三权分立的形式化分析.通过分析,给出三权分立管理机制下,保障信息系统安全管理的条件.本文的结果在某国家级信息系统的具体建设中得到了应用.
Mandatory access control is a necessary condition for constructing a high level of security information system. In this paper, based on Biba model, we give formal analysis for power sepa- ration mechanism under the condition which administrators are divided into system administra- tors, security administrators and security auditors, through the analysis, we give the conditions of guaranteeing the security of the information system management under separation of the three powers management mechanism. The results of this paper have been applied to the construction of a national information system.