斜槽,工具它分散了信息流动控制(DIFC ) ,允许高安全级别进程到预先创造在一个低安全级别目录的秘密文件。然而,预先创造机制使某正常系统成为无法获得的调用,并且而且,创造对象的大数量需要 priori 知识,它是困难的在实际操作系统估计。在这篇论文,我们在场扩大斜槽文件存取控制机制,命名效果,代替机制预先创造,许可证给它写操作(创造,删除,并且重命名一个文件)在目录上并且创造文件存取与不干涉性质为每进程分配运作的看法的虚拟层。最后,我们进一步在效果的安全上介绍分析。我们的工作使让多用户在分散的信息流动控制系统分享机密信息更容易。
Flume, which implements decentralized information flow control (DIFC), allows a high security level process to "pre-create" secret files in a low security level directory. However, the pre-create mechanism makes some normal system calls unavailable, and moreover, it needs priori knowledge to create a large quantity of objects, which is difficult to estimate in practical operating systems. In this paper, we present an extended Flume file access control mechanism, named Effect, to substitute the mechanism of pre-create, which permits write operations (create, delete, and rename a file) on directories and creates a file access virtual layer that allocates operational views for each process with noninterference properties. In the end, we further present an analysis on the security of Effect. Our work makes it easier for multi-user to share confidential information in decentralized information flow control systems.