Dissertation > Excellent graduate degree dissertation topics show
Research and Implement of Flexible Role Management in KYLIN OS
Author: LiWenBo
Tutor: LiaoXiangKe;LiZuoZuo
School: National University of Defense Science and Technology
Course: Computer Science and Technology
Keywords: Authentication trustworthiness The role of dynamic conversion The role of the transfer
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 16
Quote: 1
Read: Download Dissertation
Abstract
|
Access control is a hot research of operating system security problem. KYLIN operating system kernel role given the right to mandatory access control framework (RBA), used to protect the system security. To reduce the complexity of the policy configuration, RBA introduced the thought of the role given the right to assume a role, that user roles determine permissions. In this way, the relationship of the roles and access control policy can be determined by professionals to facilitate the management. The role, however, given the right to bring convenience, but also to the use of the system increased burden. First, the role privileges determines the user's permissions when users need to perform some restricted operation, regardless of previous certification requires landfall again choose another role, reducing the flexibility of the application. Secondly, the existing KYLIN operating system did not do a strict definition of the relationship of the users and roles, and easily lead to chaotic management system. Therefore, this paper extends the existing role management strategy KYLIN operating system, a flexible role management methods mainly include: (1) for the conversion of the role need to repeat Login problems extended RBAC model and a support role dynamic conversion of DRT-RBAC model, DRT-RBAC model reasoning model based on the credibility of the certification, the credibility and the role of user authentication conversion associated with the current role of the conversion range is determined based on the user's credibility. Meanwhile, this paper proposes a method based on the implicit role of difference metric conversion. Thought through the introduction of the Analytic Hierarchy Process (AHP), the role is broken down into fine-grained system privilege - power, divided into different types according to the importance of power and to construct the power layer pairwise comparison matrix to calculate each type of power weight ratio. Based on the difference of the number of role contained between the various types of capabilities, the structural role layer paired comparison matrix, while the weight ratio based on the weights of various types of capabilities calculate the degree of difference between the two roles. (2) the problem of chaotic management role, this article explicitly define the relationship between users and roles, and a relationship consistency check. In the the kernel active role linked list, the distinction between the different types of roles, role operation, the relationship examination. On this basis, the design and implementation of a flexible role in the transfer method to solve the associated key role the user is not bit the missing system management problems. In summary, this work is to effectively solve the dynamic role of conversion and the role relationships check, to further improve the existing role management strategy KYLIN operating system.
|
Related Dissertations
- Research of the Role and Function of Linyi Authority in Investment Promotion,F127
- Optimal Design of Vertical Thermosyphon Reboiler,TQ051
- The network credibility quantity Research and Implementation mechanism,TP393.08
- Research on Trustworthiness-Based RBAC Model and Its Application,TP393.08
- Research of IRC Botnet Detection Based on Behavior,TP393.08
- Research on the Impact Analysis of Network Security Incidents Based on Simulation,TP393.08
- Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
- Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
- Analysis and research -based HTTP proxy security gateway,TP393.08
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Research and Implementation of Bot Detection Based on API Hook Technology,TP393.08
- Research on Streaming Media Detection Methods Against DoS\DDoS Attack Based on Analysis of Self-similarity,TP393.08
- Design and Implementation of Assistant Management System Server Based on Hardware Firewall,TP393.08
- Research on the Trusted Access of Terminals and Remote Attestation Technology,TP393.08
- Virus Detection Technology Based on Artificial Immune,TP393.08
- Firewall and three switch - based campus network security policy research,TP393.08
- The special trusted computing research and design of the network,TP393.08
- Data Privacy-Preserving Schemes for Cloud Computing,TP393.08
- Research on Automated Trust Negotiation Framework and A Prototype Design,TP393.08
- The Research and Realization of Unwanted Code Monitoring System Based on Heuristic Algorithm,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|