信息网络安全 ›› 2016, Vol. 16 ›› Issue (10): 1-7.doi: 10.3969/j.issn.1671-1122.2016.10.001

• •    下一篇

基于BLP的虚拟机多级安全强制访问控制系统设计与实现

池亚平1, 姜停停1(), 戴楚屏2, 孙尉1   

  1. 1. 北京电子科技学院通信工程系,北京100070
    2. 西安电子科技大学通信工程学院,陕西西安 710071
  • 收稿日期:2016-08-16 出版日期:2016-10-31 发布日期:2020-05-13
  • 作者简介:

    作者简介: 池亚平(1969—),女,北京,教授,硕士,主要研究方向为虚拟化安全、可信计算、加密技术、软件定义网络;姜停停(1989—),女,山东,硕士研究生,主要研究方向为虚拟化安全、加密技术、网络安全、云计算网络;戴楚屏(1990—),女,安徽,硕士研究生,主要研究方向为4G无线通信、无线通;孙尉(1993—),男,陕西,硕士研究生,主要研究方向为网络安全、软件定义网络。

  • 基金资助:
    北京市自然科学基金[416307];中央高校基本科研业务费[328201537]

Design and Implementation on Multilevel Security Mandatory Access Control System for Virtual Machine Based on BLP

Yaping CHI1, Tingting JIANG1(), Chuping DAI2, Wei SUN1   

  1. 1. Communication Engineering Department, Beijing Electronic Science and Technology Institute, Beijing 100070, China
    2. School of Communications Engineering, Xidian University, Xi’an Shaanxi 710071, China;
  • Received:2016-08-16 Online:2016-10-31 Published:2020-05-13

摘要:

多级安全是一种支持不同权限的用户和资源同时访问系统,同时确保用户和资源都只能访问其有权访问的信息的机制。在云计算中,不同用户或企业的虚拟机可能运行在同一台物理主机上,它们通常具有不同的安全等级,因此实现多级安全访问控制对保护虚拟机间的通信非常有意义。针对这一问题,文章通过对传统的BLP安全模型的模型元素、安全公理和状态转换规则进行修改,构建了适用于虚拟机环境的强制访问控制安全模型,借助SELinux技术,通过共享内存和授权表的方式实现了虚拟环境中的多级安全强制访问控制,有效增强了虚拟机之间、虚拟机与宿主机之间的访问的安全性。

关键词: 云计算, 虚拟机, BLP, 强制访问控制

Abstract:

Multilevel security is a mechanism that supports the simultaneous access of users and resources with different privileges, while ensuring that both users and resources can access the information that they have access to. In the cloud computing, the virtual machines that belonging to different users or enterprises may run on the same physical host, usually they have different levels of security. So it is very meaningful to implement multilevel secure access control policy to protect the virtual machine communication. In reaction to the phenomenon, mandatory access control security model that suitable for the virtual machine environment was built by modifying the model elements, security axioms and state transition rules of the traditional BLP security model. By using SELinux technology through shared memory and authorization table way, the multilevel security mandatory access control in the virtual environment was realized, that effectively enhance access security between the virtual machine and virtual machine with the host machine.

Key words: cloud computing, virtual machine, BLP, mandatory access control

中图分类号: