计算机应用 ›› 2010, Vol. 30 ›› Issue (3): 708-714.

• 网络与通信 • 上一篇    下一篇

基于不干扰理论的信道控制策略及其自动化验证方法

崔隽1,黄皓2   

  1. 1. 软件新技术国家重点实验室, 江苏南京;南京大学计算机科学与技术系,江苏南京
    2. 计算机科学与技术系
  • 收稿日期:2009-09-29 修回日期:2009-11-09 发布日期:2010-03-14 出版日期:2010-03-01
  • 通讯作者: 崔隽
  • 基金资助:
    分布式可信计算系统研究;可信操作系统新技术研发

Channel control strategy based on noninterference theory and its automated verification scheme

  • Received:2009-09-29 Revised:2009-11-09 Online:2010-03-14 Published:2010-03-01
  • Contact: Jun Cui

摘要: 通过研究信道与那些向其输入信息或从其获得信息的信息域之间直接或间接的干扰关系,来定义信道的语义和作用。明确描述和严格控制系统模块和进程之间的信息通道,有利于最大限度地保障模块或进程的完整性和可控性。所提出的信道控制策略正是基于上述目的。而针对信道控制策略复杂而不便于手工验证的特点,提出了基于通信顺序进程(CSP)的系统和策略描述方法以及基于FDR2的系统信息流策略自动化验证方法。该方法能够在少量的人工参与的情况下有效地分析信道控制策略,发现大部分存储隐蔽通道。

关键词: 不干扰模型, 信道控制, 信息流, 通信顺序进程, 形式化验证

Abstract: The authors defined the semantic description and functions of channels based on the study of the direct or indirect relation between any information domain and other domains who sent information to it or received from it. Exactly defining and strictly controlling the information channels between system modules or processes was beneficial to the integrity and controllability of the modules or processes. And in this paper, the new channel control strategy was used for this purpose. Channel control strategies were generally not easy to be manually verified because of their complexity. The authors presented an approach of describing system and strategies based on Communicating Sequential Processes (CSP) syntax and verifying the strategies in systems with automated verification tools FDR2. This approach can effectively and efficiently analyze the information channels and find out most of the storage covert channel.

Key words: noninterference model, channel control, information flow, Communicating Sequential Processes (CSP), formal verification