一种多安全域策略支持的管理机制

    Management Mechanism for Multi-domain Strategy

    • 摘要: 提出了一种基于策略的三权分立的分域管理机制.该机制依据最小特权和权值分离原则,将超级用户特权集进行划分,分别授予系统管理员、安全管理员和审计管理员.通过建立管理员间相互协作、相互制约和域间隔离机制,解决信息系统中超级用户权限过大的问题,增强系统的安全性.

       

      Abstract: According to the characteristics of the productive information system,this paper presents a policy-based management mechanism for the sub-domain separation.The mechanism is based on the least privileges and separation of duty.Super-user privileges are divided into collections that are granted to the system administrator,the security administrator,and the auditor,respectively.Through the establishment of mutual collaboration between managers,mutual constraints,and inter-domain isolation mechanisms,the problem of the excessive privileges super-user in the information system is solved and the system security is enhanced.

       

    /

    返回文章
    返回