Netinfo Security ›› 2016, Vol. 16 ›› Issue (10): 47-53.doi: 10.3969/j.issn.1671-1122.2016.10.008

• Orginal Article • Previous Articles     Next Articles

Research on Formalized Description of Application Security

Mingde ZHANG1, Maning BI2, Shun WANG3, Qingguo ZHANG4   

  • Received:2016-09-15 Online:2016-10-31 Published:2020-05-13

Abstract:

With the gradual increase of applications within organizations, the issues of application-security have become increasingly prominent. Due to the complexity and variety of applications and their security, how to reasonably express application-security becomes a difficult problem. Existing researches on application-security focus only on some aspects or lack of pertinence, and there is still no systematically formalized model for application-security at present. This paper presents formalized description for applications through analyzing subject-object access mechanism and distinguishing business functions, security functions and application policies. Then formalized descriptions for two most common security functions (authentication and authorization) are given. In authorization, based on the concept of secrecy introduced, three kinds of roles (position role, business role and secrecy role) and object’s degrees of secrecy are analyzed, and authority manager, authority verifier and authority relying party are differentiated. Meanwhile, four unified-management policies and their formalized description are proposed through the introduction of users’ identity information and unified portal.

Key words: application security, authentication, authorization, unified management

CLC Number: