A mandatory access control framework in virtual machine system with respect to multi-level security I: Theory

Qian Liu, Guanhai Wang, Chuliang Weng, Yuan Luo, Minglu Li

Research output: Contribution to journalArticlepeer-review

12 Scopus citations

Abstract

At present, there are few security models which control the communication between virtual machines (VMs). Moreover, these models are not applicable to multi-level security (MLS). In order to implement mandatory access control (MAC) and MLS in virtual machine system, this paper designs Virt-BLP model, which is based on BLP model. For the distinction between virtual machine system and nonvirtualized system, we build elements and security axioms of Virt-BLP model by modifying those of BLP. Moreover, comparing with BLP, the Number of state transition rules of Virt-BLP is reduced accordingly and some rules can only be enforced by trusted subject. As a result, Virt-BLP model supports MAC and partial discretionary access control (DAC), well satisfying the requirement of MLS in virtual machine system. As space is limited, the implementation of our MAC framework will be shown in a continuation.

Original languageEnglish
Pages (from-to)137-143
Number of pages7
JournalChina Communications
Volume7
Issue number4
StatePublished - Oct 2010
Externally publishedYes

Keywords

  • Mandatory access control
  • Multi-level security
  • Virt-BLP
  • Virtual machine system

Fingerprint

Dive into the research topics of 'A mandatory access control framework in virtual machine system with respect to multi-level security I: Theory'. Together they form a unique fingerprint.

Cite this