SELinux-based integrity model implementation method and device

By configuring complete-level rules in the SELinux tag system and extending SELinux to support the integrity model, the problem that the Linux system cannot detect data confidentiality and integrity at the same time is solved, and the dual protection of data is achieved and the security of data access is improved.

CN119939615AInactive Publication Date: 2025-05-06北京长擎量子技术有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411665558.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-05-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing Linux systems cannot detect the confidentiality and integrity of data at the same time, and cannot take into account the confidentiality and accuracy of data.

Method used

By configuring complete-level rules and configuring them into the SELinux tag system, extending the SELinux tag system to support the integrity model ensures that the Linux system has the function of detecting data confidentiality and integrity at the same time.

Benefits of technology

It realizes the protection of data security from both confidentiality and integrity, improves the security of data access, and reduces data maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939615A_ABST
    Figure CN119939615A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and discloses an integrity model implementation method and device based on SELinux, and the method comprises the steps: configuring an integrity level rule, and configuring the integrity level rule into an SELinux label system to obtain the SELinux label system with an integrity level label; setting a Linux strategy file according to the label system with the complete-level label; and obtaining a subject tag of the target subject and an object tag of the target object, and determining an access permission of the target subject to the target object according to the Linux policy file. According to the method, the SELinux label system is expanded by configuring the integrity level rule, the support of the integrity model is increased, and the compatibility with the original SELinux security policy is kept, so that the Linux system has the function of detecting the data confidentiality and integrity at the same time, the data maintenance cost is effectively reduced, and the data security can be protected from the two aspects of confidentiality and integrity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an integrity model method and device based on SELinux. Background Art

[0002] Security-Enhanced Linux (SELinux) is a powerful labeling system that controls the access rights granted by the kernel to each process. Each process in the system has a label, and each file, directory, device, and network port in the system has a corresponding label. The most important feature of SELinux is type enforcement. The policy rules define the access rights of the subject (process) to the object (labeled files, folders, etc.). The security mechanism of SELinux includes: Role-Based Access Control (RBAC), Type Enforcement (TE), and Multi-Level Security (MLS). Among them, MLS comes from the BLP model. The purpose of the BLP model is to prevent information leakage. The BLP model is roughly as follows: processes and files have security labels. The labels have two items: sensitivity and group. Under the BLP model, there are two ways for processes to operate files: read and write. The read and write rules are: low-sensitivity processes cannot read high-sensitivity files, and high-sensitivity processes cannot write low-sensitivity files, that is, "no reading" and "no writing"; when the process group contains or is equal to the file group, the process can operate the file.

[0003] The Biba security model is a security model based on access control. The Biba security model was developed after the BLP model. Unlike the BLP model, which focuses on the confidentiality of information, the Biba model focuses on data integrity. The goal is to ensure the accuracy and consistency of data and prevent unauthorized modification and destruction. The Biba security model is mainly used to solve the integrity problem of application data. The Biba model stipulates that the necessary condition for a subject to access an object is that the integrity level of the subject is not less than the integrity level of the object. The subject can only read objects with an integrity level equal to or higher than its own, but cannot read objects with a lower integrity level than its own, that is, the subject cannot read downward; the integrity level of the subject is lower than the integrity level of the object, and the object cannot be modified, that is, the subject cannot write upward.

[0004] Both the BLP model and the Biba model belong to the mandatory access control (MAC) model, and are two important models in the field of information security. However, the two models have different focuses. The BLP model focuses on confidentiality and is described as "reading from the bottom and writing from the top", with information flowing in from the bottom to the top; while the BiBa model focuses on integrity and solves the problem of data integrity within the system. The Biba model uses integrity levels to prevent data from flowing from any low integrity level to a higher integrity level, and information can only flow from top to bottom in the system. Currently, there is no access control solution based on these two security models in the Linux system at the same time, and it is impossible to take into account both the confidentiality and integrity of data within the Linux system. Summary of the invention

[0005] In view of this, the present invention provides a method and device for implementing an integrity model based on SELinux to solve the problem that the existing Linux system cannot detect data confidentiality and integrity at the same time.

[0006] In a first aspect, the present invention provides a method for implementing an integrity model based on SELinux, the method comprising:

[0007] Configure complete level rules and configure the complete level rules into the SELinux label system to obtain the SELinux label system with complete level labels;

[0008] Set up Linux policy files based on the SELinux labeling system with full-level labels;

[0009] The SELinux subject label of the target subject and the SELinux object label of the target object are obtained, and the access rights of the target subject to the target object are determined according to the Linux policy file.

[0010] The SELinux-based integrity model implementation method provided by the present invention expands the SELinux label system by configuring integrity-level rules, adds support for the integrity model in the SELinux label system, maintains compatibility with the original SELinux security policy, enables the Linux system to simultaneously have the function of detecting data confidentiality and integrity, effectively solves data maintenance costs, and can protect data security from both confidentiality and integrity aspects.

[0011] In an optional implementation, configuring a complete level rule includes:

[0012] According to the integrity from high to low, the integrity level is divided into four levels: first integrity, second integrity, third integrity, and undefined;

[0013] All level subjects have the authority to read and write objects of the same integrity level as the subject, undefined subjects have the authority to read and write objects of all levels, and all level subjects have the authority to read and write objects of undefined levels;

[0014] A subject with a high integrity level has write-only permission to an object with a low integrity level, and a subject with a low integrity level has read-only permission to an object with a high integrity level.

[0015] The SELinux-based integrity model implementation method provided by the present invention determines the access rights of data from the integrity aspect by configuring integrity-level rules, covers the rules of all integrity access rights, is conducive to determining the access rights of the subject to the object according to the integrity-level label, realizes the integrity protection of the data through the integrity-level rules, and improves the security of data access.

[0016] In an optional implementation, the SELinux label system with a complete level label includes:

[0017] User labels, role labels, type labels, confidentiality level labels, and completeness level labels.

[0018] The SELinux-based integrity model implementation method provided by the present invention ensures support for the full set of policies of the original SELinux label system by adding a complete-level label after the confidential-level label of the original SELinux label system, increases access control of the integrity model, expands the security access control management scope of the SELinux label system, and improves the use flexibility of the SELinux label system.

[0019] In an optional implementation, determining the access rights of the target subject to the target object according to the Linux policy file includes:

[0020] An access control vector table is formed based on the SELinux label system with a complete level label;

[0021] Determine the rule permissions between different level tags according to the access control vector table;

[0022] Based on the rule permissions between labels of different levels, the access rights of the target subject to the target object are determined according to the SELinux subject label and the SELinux object label.

[0023] The SELinux-based integrity model implementation method provided by the present invention determines a policy file identifiable by the Linux kernel system according to a SELinux label system with an integrity level label, so that the kernel system can determine the user's access rights to internal resources according to the policy file, thereby improving the security of internal resources.

[0024] In an optional implementation, the target subject's access rights to the target object include: no access, read and write, read-only, and write-only. The target subject's access rights to the target object are determined according to the SELinux subject label and the SELinux object label, including:

[0025] When the role-based access control and type-enhanced policies allow a subject to access an object, if the confidentiality level labels are exactly the same, the target subject's access rights to the target object are determined according to the integrity rule;

[0026] When the role-based access control and type-enhanced policies allow a subject to access an object, if the integrity-level labels are exactly the same, the target subject's access rights to the target object are determined according to the confidentiality access rules;

[0027] When role-based access control and type-enhanced policies allow a subject to access an object, the target subject's access rights to the target object are determined according to integrity rules and confidentiality access rules.

[0028] The SELinux-based integrity model implementation method provided by the present invention can formulate different security access policies according to the actual needs of users. By setting each label in the SELinux label system, a suitable mandatory access control policy is selected, and the access control is more flexible and meets the access control of different security needs.

[0029] In an optional embodiment, the method further includes:

[0030] If the target subject's access rights to the target object are read-write, write-only, or read-only, and there is no domain conversion rule, the target subject accesses the target object according to the access rights and obtains a new subject with an SELinux subject label;

[0031] If the target subject's access rights to the target object are read-write or write-only or read-only, and there is a domain conversion rule, a new subject tag is determined according to the domain conversion rule, and the new subject tag is assigned to the new subject.

[0032] The SELinux-based integrity model implementation method provided by the present invention continues the domain conversion rules of the original SELinux label system, allowing the subject to access files or other processes that are incompatible with it, ensuring support for the full set of policies of the original SELinux label system, and increasing the access control of the integrity model, making the access control of the SELinux label system more comprehensive.

[0033] In a second aspect, the present invention provides a device for implementing an integrity model based on SELinux, the device comprising:

[0034] A complete level rule configuration module is used to configure complete level rules and configure the complete level rules into the SELinux label system to obtain a SELinux label system with complete level labels;

[0035] A policy file setting module, used to set the Linux policy file according to the SELinux label system with a complete level label;

[0036] The access authority determination module is used to obtain the SELinux subject label of the target subject and the SELinux object label of the target object, and determine the access authority of the target subject to the target object according to the Linux policy file.

[0037] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0038] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to cause a computer to execute the method of the first aspect or any corresponding embodiment thereof.

[0039] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions for causing a computer to execute the method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0041] Figure 1 is a flow chart of a method for implementing an integrity model based on SELinux according to an embodiment of the present invention;

[0042] Figure 2 is a working framework diagram of SELinux in the SELinux-based integrity model implementation method according to an embodiment of the present invention;

[0043] Figure 3 is a flow chart of another SELinux-based integrity model implementation method according to an embodiment of the present invention;

[0044] Figure 4 It is a flow chart of access control through integrity-level rules in the SELinux label system in the SELinux-based integrity model implementation method according to an embodiment of the present invention;

[0045] Figure 5 is a structural block diagram of a device for implementing an integrity model based on SELinux according to an embodiment of the present invention;

[0046] Figure 6 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0047] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0048] The embodiment of the present invention provides a method for implementing an integrity model based on SELinux, which expands the SELinux label system by configuring integrity-level rules to achieve the effect of enabling the Linux system to detect data confidentiality and integrity at the same time.

[0049] According to an embodiment of the present invention, an embodiment of a method for implementing an integrity model based on SELinux is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0050] In this embodiment, a method for implementing an integrity model based on SELinux is provided, which can be used in the above-mentioned computer system. Figure 1 is a flow chart of a method for implementing an integrity model based on SELinux according to an embodiment of the present invention, such as Figure 1 As shown, the process includes the following steps:

[0051] Step S101, configure complete level rules, and configure the complete level rules into the SELinux label system to obtain a SELinux label system with a complete level label.

[0052] Specifically, the integrity level rules are configured according to the Biba model, which is only used as an example, but not limited to this. The Biba model stipulates that the necessary condition for a subject to access an object is that the integrity level of the subject is not less than the integrity level of the object. The subject can only read objects with the same or higher integrity level as itself, but cannot read objects with lower integrity level than itself, that is, the subject cannot read downward; the integrity level of the subject is lower than the integrity level of the object, and the object cannot be modified, that is, the subject cannot write upward.

[0053] Add support for the integrity level in the SELinux label system, that is, support for the Biba model. To achieve this function, it is necessary to implement it from both the kernel and the upper-level applications of the Linux system. Add integrity-level labels to the SELinux label system in the kernel to implement the kernel's support for the integrity level; in the upper-level applications, modify the code design to implement the adaptation, setting, saving, viewing, loading and other operations of the integrity level of the SELinux label system in the kernel.

[0054] Step S102, setting a Linux policy file according to the SELinux label system with a complete level label.

[0055] Specifically, the policy files in the Linux system are various preset rules used to control the permissions, access control, security policies, etc. of users and processes, including but not limited to: the default labels of files and various access control rules between labels such as file reading, writing, execution, label setting, switching and domain transfer rules and permissions.

[0056] The purpose of kernel loading policy files includes: forming an access control vector table in the kernel so that the kernel can determine the access rights of various subject tags to object tags based on the access control vector table. The control rules contained in the policy file can be formulated by the user according to his own needs. It can be automatically loaded when the system starts or can be manually loaded by the user through commands after the system starts.

[0057] Step S103, obtaining the SELinux subject label of the target subject and the SELinux object label of the target object, and determining the access rights of the target subject to the target object according to the Linux policy file.

[0058] Specifically, Figure 2The figure shows the working framework of SELinux. The kernel layer loads the policy file of the user layer to form an access control matrix (that is, the access control vector table). In the Linux system, each application process and all resources inside the Linux system have their own SELinux label system. When the process application of the user layer needs to access related files or socket resources, it will fall from the user state to the kernel state during the running process. The Linux Security Modules (LSM) framework is used to query the access control matrix to determine whether the process is allowed to access the resources and the access rights.

[0059] The SELinux-based integrity model implementation method provided in this embodiment expands the SELinux label system by configuring integrity-level rules, adds support for the integrity model in the SELinux label system, maintains compatibility with the original SELinux security policy, and enables the Linux system to simultaneously have the function of detecting data confidentiality and integrity, effectively reducing data maintenance costs, and protecting data security from both confidentiality and integrity aspects.

[0060] In this embodiment, a method for implementing an integrity model based on SELinux is provided, which can be used in the above-mentioned computer system. Figure 3 is a flow chart of a method for implementing an integrity model based on SELinux according to an embodiment of the present invention, such as Figure 3 As shown, the process includes the following steps:

[0061] Step S201, configure complete level rules, and configure the complete level rules into the SELinux label system to obtain a SELinux label system with a complete level label.

[0062] Specifically, the above step S201 includes:

[0063] Step S2011, classifying the integrity level into four levels from high to low, namely, first integrity, second integrity, third integrity, and undefined.

[0064] Specifically, according to the Biba model, the integrity level is designed into four levels from high to low, namely, first integrity iH, second integrity iM, third integrity iL, and undefined iU. The first integrity iH, second integrity iM, and third integrity iL correspond to high, medium, and low integrity levels respectively. Undefined iU means undefined integrity level, that is, access control is not restricted by the Biba model.

[0065] Step S2012: All levels of subjects have the authority to read and write objects with the same integrity level as the subject, undefined subjects have the authority to read and write objects of all levels, and all levels of subjects have the authority to read and write objects of undefined levels.

[0066] Step S2013: The subject at the high integrity level has write-only permission to the object at the low integrity level, and the subject at the low integrity level has read-only permission to the object at the high integrity level.

[0067] Specifically, as shown in Table 1, it is an access control matrix of integrity level, which specifies different access rights of subjects of different integrity levels to objects. As can be seen from Table 1, subjects of all levels have the right to read and write objects of the same integrity level as the subject, undefined subjects have the right to read and write objects of all levels, and subjects of all levels have the right to read and write objects of undefined levels. Subjects of high integrity level have write-only permission to objects of low integrity level, and subjects of low integrity level have read-only permission to objects of high integrity level.

[0068] Table 1

[0069]

[0070] The SELinux-based integrity model implementation method provided in this embodiment determines the access rights to data from the integrity aspect by configuring integrity-level rules, and covers the rules for all integrity access rights, which is beneficial for determining the subject's access rights to the object based on the integrity-level label, and realizing the integrity protection of data through integrity-level rules, thereby improving the security of data access.

[0071] In some optional implementations, the SELinux labeling system with full-level labels includes:

[0072] User labels, role labels, type labels, confidentiality level labels, and completeness level labels.

[0073] Specifically, for the SELinux label system, any resource has its own label. The original SELinux label system includes: user label SELinux user, role label SELinux role, type label SELinux type, and confidentiality label sensitivity level. The security context format of the original SELinux label is: sysadm_u:sysadm_r:sysadm_t:s0-s15:c0.c1023. Based on the original SELinux label system, it is expanded to increase its support for the integrity level. The integrity level label is added after the confidentiality level label of the security label. After the expansion, the integrity level label is added at the end of the security context. The security context format of the SELinux label is: sysadm_u:sysadm_r:sysadm_t:s0-s15:c0.c1023:iU, which realizes the support for the integrity level, ensures the support for the original SELinux full set of policies, and adds the Biba model for integrity access control. When the integrity level label in the SELinux label is iU, it means that the integrity level rules of the Biba model do not work, and only security access control is performed from the confidentiality level.

[0074] The SELinux-based integrity model implementation method provided in this embodiment ensures support for the full set of policies of the original SELinux labeling system by adding an integrity-level label after the confidential-level label of the original SELinux labeling system, increases access control of the integrity model, expands the security access control management scope of the SELinux labeling system, and improves the flexibility of use of the SELinux labeling system.

[0075] Step S202, setting a Linux policy file according to the SELinux label system with a complete level label. Figure 1 The description of step S101 shown is not repeated here.

[0076] Step S203, obtaining the SELinux subject label of the target subject and the SELinux object label of the target object, and determining the access rights of the target subject to the target object according to the Linux policy file.

[0077] Specifically, the above step S203 includes:

[0078] Step S2031, forming an access control vector table according to the SELinux label system with the complete level label.

[0079] Specifically, users can customize the access control policies they need according to their needs. When the policy is executed and the system is started, the kernel will load the policy file to form an access control vector table. You can also use commands to reload the policy file. When the kernel loads the policy file, it parses the rules of the policy file and converts them into an access control vector table that the kernel can understand.

[0080] Step S2032, determining the rule permissions between tags of different levels according to the access control vector table.

[0081] Specifically, the Linux system kernel can directly determine the rule permissions between different levels of labels based on the access control vector table, including the full-level rules shown in Table 1 and the access policies between different labels in the original SELinux label system. The access policies between different labels in the original SELinux label system are mature existing technologies and will not be repeated here.

[0082] Step S2033, based on the rule permissions between the different level labels, the access rights of the target subject to the target object are determined according to the SELinux subject label and the SELinux object label.

[0083] Specifically, based on the rule permissions between labels of different levels, the target subject's access rights to the target object are determined. If the target subject's access rights to the target object are judged to be "write-only" based on the confidentiality label, and the target subject's access rights to the target object are judged to be "read-write" based on the integrity label, then the target subject's access rights to the target object are ultimately judged to be "write-only", and the access right with the smallest scope shall prevail to ensure the security of the data in the object.

[0084] like Figure 4 The figure shows a flowchart of access control through integrity level rules in the SELinux label system. All resources in the Linux system are assigned corresponding integrity level labels. The default integrity level label of resources that are not specially marked by users is "undefined iU". Users set appropriate integrity level labels for the resources they need to protect; set appropriate integrity level labels for SELinux users in the SELinux label system, and bind Linux users to SELinux users to set integrity level labels for Linux users. When Linux users start application processes, they inherit the integrity level labels of Linux users by default, and follow integrity level rules when accessing Linux internal resources. During the startup process, the subject (user, process) and the object (resource, file) all have their own integrity level labels. For example, when a user logs in to a command terminal (bash terminal), the Linux kernel assigns the corresponding integrity level to this bash according to the user's integrity level. The user uses this bash to start an executable file, and the subject label is the security label of this bash.

[0085] When a process accesses a resource, it enters kernel state from user state. The kernel queries the access control vector table based on the LSM framework to determine whether the process has relevant access rights to the resource and the specific access right type (read-write, read-only, write-only).

[0086] It should be noted that during the configuration phase, the security administrator pre-configures files and users at the user level, and the policy items in the policy file are not applied. The label setting for the subject and object is done by the slinux module in the kernel based on the user's configuration file.

[0087] The SELinux-based integrity model implementation method provided in this embodiment determines a policy file recognizable by the Linux kernel system according to the SELinux label system with an integrity level label, so that the kernel system can determine the user's access rights to internal resources according to the policy file, thereby improving the security of internal resources.

[0088] In some optional implementations, the target subject's access rights to the target object include: no access, read and write, read-only, and write-only. The above step S2033 includes:

[0089] Step a1: When the role-based access control and type-enhanced policies allow the subject to access the object, if the confidentiality level labels are exactly the same, the access rights of the target subject to the target object are determined according to the integrity rule.

[0090] Step a2: When the role-based access control and type-enhanced policies allow the subject to access the object, if the integrity level labels are exactly the same, the access rights of the target subject to the target object are determined according to the confidentiality access rules.

[0091] Step a3: When the role-based access control and type-enhanced policies allow the subject to access the object, the access rights of the target subject to the target object are determined according to the integrity and confidentiality access rules.

[0092] Specifically, the user label in the SELinux label system follows the access control rules of the role, and the type label follows the type enhancement (TE) strategy. The role-based access control rules and type enhancement (TE) strategy not only include relevant permission controls for reading and writing, but also include rule controls such as execution permissions and domain conversion, etc., which are only used as examples, but not limited to this. The BLP model and the Biba model mainly perform security access control from the aspects of read and write permissions. When the role-based access control and type enhancement strategy allow the subject to access the object, it is necessary to use the BLP model and the Biba model to control access permissions from the confidentiality level or the integrity level. If the role-based access control and type enhancement strategy do not allow the subject to access the object, there is no need to use the BLP model and the Biba model to further judge the read and write permissions.

[0093] This embodiment implements support for the BLP model through confidential-level labels in the SELinux label system, and implements support for the Biba model through complete-level labels in the SELinux label system. In practical applications, the BLP model or the Biba model or both can be selected to control access rights by setting labels. The specific label settings follow the rules of the BLP model or the Biba model, which will not be repeated here.

[0094] It should be noted that a file can be a file inside the Linux system or a network port or a network connection. Everything in the Linux system is a file.

[0095] The SELinux-based integrity model implementation method provided in this embodiment can formulate different security access policies according to the actual needs of users. By setting each label in the SELinux label system, an appropriate mandatory access control policy is selected, and access control is more flexible to meet access control with different security needs.

[0096] In some optional embodiments, the method further comprises:

[0097] If the target subject's access rights to the target object are read-write or write-only or read-only, and there is no domain conversion rule, the target subject accesses the target object according to the access rights and obtains a new subject with a SELinux subject label.

[0098] If the target subject's access rights to the target object are read-write or write-only or read-only, and there is a domain conversion rule, a new subject tag is determined according to the domain conversion rule, and the new subject tag is assigned to the new subject.

[0099] Specifically, when a user starts a process to access an executable file, the kernel will determine whether the process has execution permission for the executable file based on the SELinux label of the process and the SELinux label of the executable file. If not, the process cannot execute the executable file; if there is and there is no domain transition rule, the new process after starting the executable file has the same SELinux label as the original process; if the original process has execution permission for the executable file and there is a domain transition rule, it is converted into a corresponding new label according to the domain transition rule. The domain transition rule is a mature existing technology and will not be described here.

[0100] The SELinux-based integrity model implementation method provided in this embodiment continues the domain conversion rules of the original SELinux label system, allowing the subject to access files or other processes that are incompatible with it, ensuring support for the full set of policies of the original SELinux label system, and increasing the access control of the integrity model, making the access control of the SELinux label system more comprehensive.

[0101] In this embodiment, a device for implementing an integrity model based on SELinux is also provided, and the device is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0102] This embodiment provides a device for implementing an integrity model based on SELinux, such as Figure 5 As shown, including:

[0103] The complete level rule configuration module 501 is used to configure complete level rules and configure the complete level rules into the SELinux label system to obtain the SELinux label system with complete level labels.

[0104] The policy file setting module 502 is used to set the Linux policy file according to the SELinux label system with the complete level label.

[0105] The access authority determination module 503 is used to obtain the SELinux subject label of the target subject and the SELinux object label of the target object, and determine the access authority of the target subject to the target object according to the Linux policy file.

[0106] In some optional implementations, the complete level rule configuration module 501 includes:

[0107] The level division unit is used to divide the integrity level into four levels: first integrity, second integrity, third integrity, and undefined according to the integrity from high to low.

[0108] The read and write permission determination unit is used to ensure that all levels of subjects have the permission to read and write objects with the same integrity level as the subject, undefined subjects have the permission to read and write objects of all levels, and all levels of subjects have the permission to read and write objects of undefined levels.

[0109] The read-only and write-only permission determination unit is used to allow a subject at a high integrity level to have write-only permission on an object at a low integrity level, and a subject at a low integrity level to have read-only permission on an object at a high integrity level.

[0110] In some optional implementations, the access authority determination module 503 includes:

[0111] The access control vector table determination unit is used to form an access control vector table according to the SELinux label system with a complete level label.

[0112] The rule authority determination unit is used to determine the rule authority between tags of different levels according to the access control vector table.

[0113] The access permission determination unit is used to determine the access permission of the target subject to the target object based on the rule permissions between the labels of different levels and according to the SELinux subject label and the SELinux object label.

[0114] In some optional implementations, the target subject's access rights to the target object include: no access, read and write, read-only, and write-only, and the access rights determination unit includes:

[0115] Integrity control subunit, when role-based access control and type-enhanced policies allow a subject to access an object, if the confidentiality level labels are exactly the same, the target subject's access rights to the target object are determined according to the integrity rules.

[0116] Confidentiality level control subunit, when role-based access control and type-enhanced policies allow a subject to access an object, if the integrity level labels are exactly the same, the target subject's access rights to the target object are determined according to the confidentiality access rules.

[0117] The security control subunit determines the access rights of the target subject to the target object according to the integrity rule and confidentiality access rule when the role-based access control and type-enhanced policy allow the subject to access the target object.

[0118] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0119] The SELinux-based integrity model implementation device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0120] The embodiment of the present invention also provides a computer device having the above Figure 5 The SELinux-based integrity model implementation device is shown.

[0121] See also Figure 6 , Figure 6 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.

[0122] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0123] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0124] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0125] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0126] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0127] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0128] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0129] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for implementing an integrity model based on SELinux, characterized in that: The method comprises: Configure a complete level rule, and configure the complete level rule into the SELinux label system to obtain a SELinux label system with a complete level label; Setting a Linux policy file according to the SELinux label system with the complete level label; The SELinux subject label of the target subject and the SELinux object label of the target object are obtained, and the access rights of the target subject to the target object are determined according to the Linux policy file.

2. The method according to claim 1, characterized in that The configuration complete level rules include: According to the integrity from high to low, the integrity level is divided into four levels: first integrity, second integrity, third integrity, and undefined; All level subjects have the authority to read and write objects of the same integrity level as the subject, undefined subjects have the authority to read and write objects of all levels, and all level subjects have the authority to read and write objects of undefined levels; A subject with a high integrity level has write-only permission to an object with a low integrity level, and a subject with a low integrity level has read-only permission to an object with a high integrity level.

3. The method according to claim 1 or 2, characterized in that: The SELinux label system with a complete level label includes: User labels, role labels, type labels, confidentiality level labels, and completeness level labels.

4. The method according to claim 1, characterized in that Determining the access rights of the target subject to the target object according to the Linux policy file includes: Forming an access control vector table according to the SELinux label system with the complete level label; Determine the rule permissions between tags of different levels according to the access control vector table; Based on the rule permissions between labels of different levels, the access rights of the target subject to the target object are determined according to the SELinux subject label and the SELinux object label.

5. The method according to claim 4, characterized in that The target subject's access rights to the target object include: no access, read and write, read-only, and write-only. The target subject's access rights to the target object are determined based on the SELinux subject label and the SELinux object label, including: When the role-based access control and type-enhanced policies allow a subject to access an object, if the confidentiality level labels are exactly the same, the target subject's access rights to the target object are determined according to the integrity rule; When the role-based access control and type-enhanced policies allow a subject to access an object, if the integrity-level labels are exactly the same, the target subject's access rights to the target object are determined according to the confidentiality access rules; When role-based access control and type-enhanced policies allow a subject to access an object, the target subject's access rights to the target object are determined according to integrity rules and confidentiality access rules.

6. The method according to claim 5, characterized in that The method further comprises: If the target subject's access rights to the target object are read-write, write-only, or read-only, and there is no domain conversion rule, the target subject accesses the target object according to the access rights and obtains a new subject with an SELinux subject label; If the target subject's access rights to the target object are read-write or write-only or read-only, and there is a domain conversion rule, a new subject tag is determined according to the domain conversion rule, and the new subject tag is assigned to the new subject.

7. A device for implementing an integrity model based on SELinux, characterized in that: The device comprises: A complete level rule configuration module, used to configure complete level rules, and configure the complete level rules into the SELinux label system to obtain a SELinux label system with a complete level label; A policy file setting module, used for setting a Linux policy file according to the SELinux label system with a complete level label; The access authority determination module is used to obtain the SELinux subject label of the target subject and the SELinux object label of the target object, and determine the access authority of the target subject to the target object according to the Linux policy file.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 6 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that The method comprises computer instructions for causing a computer to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for implementing safe storage system in cloud storage environment

    CN102014133A

  • Multi-strategy integration based mandatory access control method

    CN104112089A

  • SELinux operating system security policy integrity model and integrity detection method

    CN115080980A