An access control method for an airborne embedded operating system
Patent Information
- Application Number
- CN202411666141.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-20
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2044-11-20
AI Technical Summary
[0004]本发明技术方案的目的是:针对不同种类对象设置多种的访问控制规则,以解决由于缺乏对访问者历史信用的考量,导致无法识别长期伪装的恶意对象
[0019]This invention proposes an access control method for airborne embedded operating systems. It sets up a simple traditional security level authentication method for ordinary system resources with low security risks, and sets up a security value authentication method for file/database access with high security risks. The security value is derived based on a pre-trained neural network model, which has stronger adaptability and flexibility. For partition access, a dynamic trust value authentication method is adopted, which can take into account the security of historical access behavior and realize the dynamic adjustment of trust value.
Smart Images

Figure CN119783087B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of access control security technology, and more specifically to an access control method for airborne embedded operating systems. Background Technology
[0002] In the aviation industry, the level of electronic integration of airborne systems is constantly increasing, and the proportion of software systems is growing. As a result, the security and reliability of software systems are receiving increasing attention. Therefore, in addition to providing multi-level security isolation environments for mission execution, airborne embedded operating systems also need to provide secure access control mechanisms to ensure secure interaction between objects of different security levels.
[0003] Traditional access control methods often rely on rules that remain unchanged once generated, lacking adaptability and flexibility, and making it difficult to identify cunning and ever-changing threats and risks. The single-authentication and long-term validity of traditional access control methods fail to consider the visitor's historical credit history, thus failing to identify malicious entities that have been masquerading for an extended period. Summary of the Invention
[0004] The purpose of this invention is to set up multiple access control rules for different types of objects in order to solve the problem of being unable to identify malicious objects that have been disguised for a long time due to the lack of consideration for the visitor's historical credit.
[0005] The present invention provides an access control method for an airborne embedded operating system, comprising the following steps:
[0006] The partition application in the airborne operating system submits access requests to different resources and determines whether the resource corresponding to the access request is a normal resource component;
[0007] If it is a regular resource component, then perform security level authentication between different resources and partition applications and obtain the security level access result;
[0008] If it is not a normal resource component, then continue to determine whether it is a file / database. If it is a file / database, then obtain the file / database attribute vectors of the partition application and different resources, calculate the access security value corresponding to the attribute vector according to the access security value formula, compare the access security value with the access threshold and obtain the security value access result to achieve security value authentication.
[0009] If it is not a file / database, then it continues to determine whether it is inter-regional communication. If it is inter-regional communication, it obtains the inter-regional communication attribute vectors of the partition application and different resources, calculates the mutual trust value corresponding to the attribute vector according to the mutual trust value formula, selects N communication records containing this inter-regional communication, calculates the historical mutual trust accumulation of this inter-regional communication according to the historical mutual trust accumulation formula, counts the total number of accesses, the number of positive evaluations, and the number of negative evaluations in the past θ time period, calculates the penalty / reward factor corresponding to this communication according to the penalty / reward factor formula, obtains the total trust value of this communication based on the historical mutual trust accumulation, penalty / reward factor, and number of positive evaluations of this inter-regional communication, compares the total trust value of this communication with the trust threshold, and obtains the dynamic trust value authentication result to achieve security value authentication.
[0010] If it is not inter-regional communication, then perform security level authentication between different resources and partition applications and obtain the security level access result.
[0011] Preferably, the file / database attribute vector includes: access security level, access group, and read, write, and execute permissions of the partition application for the file / database.
[0012] Preferably, the interval communication attribute vector includes: the communication security level, communication group, communication data entropy value, and communication data category of the partition application and different resources.
[0013] Preferably, the formula for accumulating historical mutual trust is as follows:
[0014]
[0015] Where, Δt j =t i -t j It is the cumulative time since the j-th (iN≤j≤i-1) communication, e is the entropy value of the communication data, and i is the current interval communication.
[0016] Preferably, the penalty / reward factor is as follows:
[0017]
[0018] Where pi represents the number of positive reviews, Mi represents the total number of visits, and ni represents the number of negative reviews.
[0019] This invention proposes an access control method for airborne embedded operating systems. It sets up a simple traditional security level authentication method for ordinary system resources with low security risks, and sets up a security value authentication method for file / database access with high security risks. The security value is derived based on a pre-trained neural network model, which has stronger adaptability and flexibility. For partition access, a dynamic trust value authentication method is adopted, which can take into account the security of historical access behavior and realize the dynamic adjustment of trust value. Attached Figure Description
[0020] Figure 1 This is a flowchart illustrating the access control process for an airborne embedded operating system in an access control method provided by an embodiment of the present invention.
[0021] Figure 2 This is a flowchart illustrating the security level authentication process in an access control method for an airborne embedded operating system, as provided in an embodiment of the present invention.
[0022] Figure 3 This is a flowchart illustrating the security value authentication process in an access control method for an airborne embedded operating system, as provided in an embodiment of the present invention.
[0023] Figure 4 This is a flowchart illustrating the dynamic trust value authentication process in an access control method for an airborne embedded operating system, as provided in an embodiment of the present invention. Detailed Implementation
[0024] The present invention will be further illustrated below with reference to specific embodiments. It should be understood that these embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, it should be understood that after reading the teachings of this invention, those skilled in the art can make various alterations or modifications to the invention, and these equivalent forms also fall within the scope defined by the appended claims.
[0025] This invention provides an access control method for airborne embedded operating systems to address security issues arising from partitioned applications accessing different resources within an airborne operating system. The method includes the following steps:
[0026] like Figure 1 As shown, the steps for access control of the airborne operating system are as follows:
[0027] Step 101: Begin.
[0028] Step 102: The partition application submits an access request.
[0029] Step 103: Determine whether the interviewee is a regular resource component. If yes, proceed to step 106; otherwise, proceed to step 104.
[0030] Step 104: Determine if the interviewee is a file / database. If yes, proceed to step 107; otherwise, proceed to step 105.
[0031] Step 105: Determine whether the interviewee is a partition (inter-partition communication). If yes, proceed to step 108; otherwise, proceed to step 106.
[0032] Step 106: Authentication based on security level, then proceed to step 110.
[0033] like Figure 2 As shown, the security level authentication includes the following steps:
[0034] Step 201: Begin.
[0035] Step 202: Obtain the confidentiality level of the interviewee and visitor.
[0036] Step 203: Compare the confidentiality levels of the interviewee and the visitor. If the interviewee's confidentiality level is equal to or lower than that of the visitor, proceed to step 204; otherwise, proceed to step 205.
[0037] Step 204: Grant access, then proceed to step 206.
[0038] Step 205: Deny this access.
[0039] Step 206: End.
[0040] Step 107: Authenticate based on the security value, then proceed to step 110.
[0041] like Figure 3 As shown, security value authentication includes the following steps:
[0042] Step 301: Begin.
[0043] Step 302: Generate the attribute vector A = [L, G, R, W, E, G', L'] for both parties, where L and L' are the security levels of both parties, G and G' are the groups of both parties, and R, W, and E are the read, write, and execute permissions of the visitors to the file / database.
[0044] Step 303: Calculate the access security value O = f1(A), where f1 is a pre-trained three-layer neural network model with seven inputs and ten outputs.
[0045] Step 304: Compare the safety value O with the threshold Othreshold. If O is greater than or equal to Othreshold, proceed to step 305; otherwise, proceed to step 306.
[0046] Step 305: Grant access, then proceed to step 307.
[0047] Step 306: Deny this access.
[0048] Step 307: End.
[0049] Step 108: Authentication is performed based on the dynamic trust value, then proceed to step 110.
[0050] like Figure 4 As shown, dynamic trust value authentication includes the following steps:
[0051] Step 401: Begin.
[0052] Step 402: Generate the attribute vector A of both parties in this (i-th) communication. i = [L,L',G,G',e,C], where L and L' are the security levels of the two communicating parties, G and G' are the groups of the two communicating parties, e is the entropy value of the communication data, and C is the category of the communication data.
[0053] Step 403: Calculate the mutual trust value P between the two parties in this communication. i =f2(A i ), where f2 is a pre-trained three-layer neural network model with six inputs and ten outputs.
[0054] Step 404: Select N communication records from the past iN to i-1 times, and calculate the historical mutual trust accumulation for this communication. Where Δt j =t i -t j It is the cumulative time since the j-th (iN≤j≤i-1) communication.
[0055] Step 405: Statistically analyze [t] within the past time interval θ. i -θ,t i The total number of visits Mi, the number of positive reviews pi, and the number of negative reviews ni are used to calculate the penalty / reward factor for this instance.
[0056] Step 406: Calculate the total trust value S for this transaction. i =ωT i +(1-ω)r i P i .
[0057] Step 407: Record the current timestamp ti and the historical mutual trust accumulation ti.
[0058] Step 408: Compare the total trust value S with the threshold Sthreshold. If S is greater than or equal to Sthreshold, proceed to step 409; otherwise, proceed to step 410.
[0059] Step 409: Grant access, then proceed to step 411.
[0060] Step 410: Deny this access.
[0061] Step 411: End.
[0062] Step 109: Deny access and throw an exception.
[0063] Step 110: Record audit information.
[0064] Step 111: End.
Claims
1. An access control method for an airborne embedded operating system, characterized in that, Includes the following steps: The partition application in the airborne operating system submits access requests to different resources and determines whether the resource corresponding to the access request is a normal resource component; If it is a regular resource component, then perform security level authentication between different resources and partition applications and obtain the security level access result; If it is not a normal resource component, then it continues to determine whether it is a file / database. If it is a file / database, then it obtains the file / database attribute vectors of the partition application and different resources, calculates the access security value corresponding to the attribute vector according to the access security value formula, compares the access security value with the access threshold and obtains the security value access result to achieve security value authentication. If it's not a file / database connection, continue to determine if it's inter-regional communication. If it is, obtain the inter-regional communication attribute vectors for the partition application and different resources. Calculate the mutual trust value corresponding to the attribute vectors according to the mutual trust value formula. Select N communication records containing this inter-regional communication data. Calculate the historical mutual trust accumulation for this inter-regional communication according to the historical mutual trust accumulation formula. Count the total number of accesses, positive reviews, and negative reviews within the past time period θ. Calculate the penalty / reward factor corresponding to this communication according to the penalty / reward factor formula. Based on the historical mutual trust accumulation for this inter-regional communication... Punishment / Reward Factors and mutual trust value Obtain the total trust value for this communication. ,in Using the coefficient as a factor, the total trust value of this communication is compared with the trust threshold to obtain the dynamic trust value authentication result, so as to realize dynamic trust value authentication; If it is not inter-regional communication, access will be denied and an exception will be thrown.
2. The access control method for an airborne embedded operating system as described in claim 1, characterized in that, The file / database attribute vector includes: access security level, access group, and read, write, and execute permissions of the partition application for the file / database.
3. The access control method for an airborne embedded operating system as described in claim 1, characterized in that, The segmented communication attribute vector includes: the communication security level, communication group, communication data entropy value, and communication data category of the segmented application and different resources.
4. The access control method for an airborne embedded operating system as described in claim 1, characterized in that, The formula for accumulating historical mutual trust is as follows: in, It is the first The cumulative time since the last communication, e is the entropy value of the communication data, and i is the current communication round in the current interval.
5. The access control method for an airborne embedded operating system as described in claim 1, characterized in that, The penalty / reward factors are as follows: in, The number of positive reviews Total number of visits This represents the number of negative reviews.
Citation Information
Patent Citations
Method for controlling multilevel access to integrated avionics system
CN101860526A
Access control method and system based on security domain isolation
CN103379089A