Netinfo Security ›› 2015, Vol. 15 ›› Issue (12): 21-27.doi: 10.3969/j.issn.1671-1122.2015.12.004

Previous Articles     Next Articles

Multi-level Security Model Based on Noninterference Theory in Cloud

ZHOU Na1, LIN Guoyuan1,2(), LI Zhengkui1   

  1. 1.School of Computer, China University of Mining and Technology, Xuzhou Jiangsu 221116, China
    2. Department of Computer, Nanjing University, Nanjing Jiangsu 210093, China
  • Received:2015-10-31 Online:2015-12-20 Published:2016-01-04

Abstract:

For the problem of the integrity of information in cloud computing, this paper proposed a multi-level security model for a cloud-based platform. The system is divided into three layers by this model and takes the process of virtual machine as a basic layer. The virtual machines run on the same virtual machine monitor are middle layer. Finally, the virtual machine monitor is the top layer. Through comparing the safety in the bottom-up order, the access control method DIFC-B (Decentralized Information Control Flow Based on Biba and BLP)based on the information flow control method of a distributed computing environment DIFC (Decentralized Information Flow Control) is proposed, which is raised for the security model. The method divides virtual machines and the processes in virtual machines into different security levels. Then according to the properties of Biba model and BLP model to verify the process between the access and to ensure the integrity and confidentiality of information when the system is running. Finally, the multi-level security model based on cloud platform is analyzed with noninterference theory, which can show the usefulness of the model.

Key words: cloud computing, multi-level security, DIFC-B access control method, noninterference

CLC Number: