Dissertation > Excellent graduate degree dissertation topics show
Research on Access Control Technology of the Enclave Boundary Based on Security Label
Author: MaXiangLin
Tutor: ZhangHongQi
School: PLA Information Engineering University
Course: Military Communication
Keywords: Area boundary Access control Safety markings Security token protection level CIPSO Group Policy Management
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 96
Quote: 1
Read: Download Dissertation
Abstract
|
The level of protection of information security is a basic policy of China's economic construction and development of information technology. Security token protection level (Level 3) construction of information systems plays an important role in the research and implementation of the level of protection of the area border security as a key technology in the construction of three information systems is the rectification of the current information system security an important issue. However, the current study area boundary focused on the application area border protection, can not effectively meet the needs of the three information systems area border security, especially for the access control of the network data stream with a security tag. At home and abroad through research area border access control technology and border security technology development status, combined with the level of protection of the technical requirements of the three standards, the establishment of a network-oriented data stream area border access control model, improved network data flow security mark binding techniques, and group-based boundary policy management technology, access control area boundary on the network data stream with security token. Topics include: (1) the establishment of the network data stream access control model for the zone boundary area boundary for the three information systems access control security needs, propose a network-oriented data flow area border access control state machine model. Define the formal description of the model, security features, security system status conversion rules and security theorems, the conversion rules of safety and security theorem necessary proof, and based on lattice theory to model data flow control, access control processes and performance The analysis provides a theoretical basis for the network data stream access control area boundaries. (2) improvements based on the CIPSO network data flow security token binding technical analysis of the existing network data flow security token binding technology, combined with the establishment of the regional border network data stream access control model to improve the network data stream based on CIPSO standard security token tied given technology, to define a new type of security tag, improved areas set encoding method to achieve the regional border flow of network data confidentiality, integrity control, and analysis of the regional border network data flow control procedures. (3) group-based the area border access control policy management technology for regional border access control model implemented discretionary access control and mandatory access control strategy, by the existing Group Policy Management Technology, the area border policy management group-based technology, gives the area boundary on the group-based policy management mechanisms and policy management framework and management performance. (4) design area border security gateway prototype system on the basis of the area boundary network data stream access control model and group-based regional border policy management technology, given the overall design of the regional border gateway for the three information systems and gateway module - security management platform, access control ruling module, security audit management module gives concrete realization.
|
Related Dissertations
- Study on Channel Allocation of Multi-Channel MAC Protocol in Ad-Hoc Network,TN929.5
- The Design and Implementation of DICOM Middle Software and Access Control Model in Formation Integration Platform,TP311.13
- Research on MAC Protocol for WIreless Sensor Network,TN915.04
- Study on the Access Control of the Court Information System,TP309
- The Design and Implementation of Higher People’s Court Website That Based on Component and ASP Technology,TP311.52
- Design and implementation of civil explosive industry online procurement system,TP311.52
- Research and Design of Virtual Research Center System of Yalong River Based on S2SH,TP311.52
- Fujian Telecom operation and maintenance operations audit system design and implementation,TP311.52
- Research on Purpose-based Access Control in Relational Database,TP311.13
- Research on Checking and Digesting Policy Conflicts Under Multi-Policy Environments,TP393.08
- Research and Implementation of Embeded Web System Security,TP393.08
- Research and Implementation on Smartcard Database Management System,TP311.52
- Design and Implement of Frequency EOC System and Research of Its Security Mechanism,TN915.02
- Identity-Based Authentication System Research and Implementation,TN918.1
- Converged IP and FC storage system security architecture design and implementation,TP333
- Distributed Storage System Security Key Technology Research and Implementation,TP333
- Virtual domain access control system protection mechanisms,TP309.2
- Access control policies based on predicates Analysis System,TP393.08
- Target tracking in distributed sensor scheduling,TN929.5
- Electronic file operations safety monitoring technology research,TP309
- Origins sensor data privacy protection technology research and application,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|