{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,3]],"date-time":"2022-04-03T01:14:06Z","timestamp":1648948446838},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2007,6,1]],"date-time":"2007-06-01T00:00:00Z","timestamp":1180656000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["SCI CHINA SER F"],"published-print":{"date-parts":[[2007,6]]},"DOI":"10.1007\/s11432-007-0028-3","type":"journal-article","created":{"date-parts":[[2007,6,27]],"date-time":"2007-06-27T16:56:59Z","timestamp":1182963419000},"page":"399-418","source":"Crossref","is-referenced-by-count":3,"title":["Design of secure operating systems with high security levels"],"prefix":"10.1007","volume":"50","author":[{"given":"SiHan","family":"Qing","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"ChangXiang","family":"Shen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"28_CR1","first-page":"123","volume-title":"Proceedings of the 8th USENIX Security Symposium","author":"R. Spencer","year":"1999","unstructured":"Spencer R, Smalley S, Loscocco P, et al. The Flask security architecture: System support for diverse security policies. In: Proceedings of the 8th USENIX Security Symposium. Washington DC: Usenix Assoc., 1999. 123\u2013139"},{"key":"28_CR2","unstructured":"Wright C, Cowan C, Morris J, et al. Linux security modules: General security support for the Linux kernel. Usenix Security Symp., Usenix Assoc., 2002. 17\u201331"},{"key":"28_CR3","unstructured":"Kuhnhauser W, Ostrowski M. A framework to support multiple security policies. In: Proceedings of the 7th Canadian Computer Security Symposium, Ottawa, Canada, 1995"},{"key":"28_CR4","doi-asserted-by":"crossref","unstructured":"Bell D E. Modeling the multipolicy machine. In: Proc. of the New Security Paradigm Workshop, 1994, 2\u20139","DOI":"10.1109\/NSPW.1994.656208"},{"key":"28_CR5","doi-asserted-by":"crossref","unstructured":"Bell D E, La Padula L J. Secure Computer System: Unified Exposition and Multics Interpretation. Mitre Report, MTR-2997 Rev. 1, 1976","DOI":"10.21236\/ADA023588"},{"key":"28_CR6","unstructured":"Ott A. Regel-Basierte zugriffskontrolle nach dem Generalized framework for access controlansatz am beispiel Linux. Diplomarbeit Universitat Hamburg, 1997"},{"key":"28_CR7","first-page":"140","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"T. Lee","year":"1988","unstructured":"Lee T. Using mandatory integrity to enforce \u201ccommercial\u201d security. In: Proceedings of IEEE Symposium on Security and Privacy. Oakland: IEEE Computer Society Press, 1988. 140\u2013146"},{"key":"28_CR8","first-page":"212","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"D. E. Bell","year":"1988","unstructured":"Bell D E. Security policy modeling for the next-generation packet switch. In: Proceedings of IEEE Symposium on Security and Privacy. Oakland: IEEE Computer Society Press, 1988. 212\u2013216"},{"key":"28_CR9","first-page":"368","volume-title":"Proc of the 4th Aerospace Computer Security Application","author":"F. L. Mayer","year":"1988","unstructured":"Mayer F L. An interpretation of refined Bell-La Padula model for the TMach kernel. In: Proc of the 4th Aerospace Computer Security Application. Orlando: IEEE Computer Society Press, 1988. 368\u2013378"},{"key":"28_CR10","unstructured":"Secure Computing Corporation. Assurance in the Fluke microkernel: Formal top-level specification. CDRL A004. Technical Report, Secure Computing Corporation, 1999"},{"issue":"10","key":"28_CR11","first-page":"1547","volume":"15","author":"Q. G. Ji","year":"2004","unstructured":"Ji Q G, Qing S H, He Y P. An improved dynamically modified confidentiality policies model. J Software (in Chinese), 2004, 15(10): 1547\u20131557","journal-title":"J Software (in Chinese)"},{"key":"28_CR12","unstructured":"Biba K. Integrity consideration for secure computer systems. MITRE TR-3153, MITRE Corporation, 1977"},{"key":"28_CR13","first-page":"184","volume-title":"IEEE Symposium on Security and Privacy","author":"D. Clark","year":"1987","unstructured":"Clark D, Wilson D. A comparison of commercial and military computer security policies. In: IEEE Symposium on Security and Privacy. Oakland, CA: IEEE, 1987. 184\u2013194"},{"key":"28_CR14","first-page":"130","volume-title":"IEEE Symposium on Security and Privacy","author":"P. Karger","year":"1988","unstructured":"Karger P. Implementing commercial data integrity with secure capabilities. In: IEEE Symposium on Security and Privacy. Oakland, CA: IEEE, 1988. 130\u2013139"},{"key":"28_CR15","unstructured":"O\u2019Brien R, Rogers C. Developing applications on LOCK. In: Proc 14th National Computer Security Conference. Washington DC, 1991. 147\u2013156"},{"key":"28_CR16","unstructured":"National Security Agency, Security Enhanced Linux (SELinux). http:\/\/www.nsa.gov\/selinux 2001"},{"issue":"5","key":"28_CR17","doi-asserted-by":"crossref","first-page":"545","DOI":"10.1007\/s11432-006-2014-6","volume":"49","author":"Q. G. Ji","year":"2006","unstructured":"Ji Q G, Qing S H, He Y P. A formal model for integrity protection based on DTE technique. Sci China Ser F-Inf Sci, 2006, 49(5): 545\u2013565","journal-title":"Sci China Ser F-Inf Sci"},{"issue":"9","key":"28_CR18","doi-asserted-by":"crossref","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"J. H. Saltzer","year":"1975","unstructured":"Saltzer J H, Schroeder M D. The protection of information in computer systems. Proc IEEE, 1975, 63(9): 1278\u20131308","journal-title":"Proc IEEE"},{"key":"28_CR19","unstructured":"Ferraiolo D, Cugini J, Kuhn D. Role based access control (RBAC): Features and motivations. In: Proceedings of 11th Annual Computer Security Applications Conference, 1995"},{"key":"28_CR20","doi-asserted-by":"crossref","unstructured":"Hoffman J. Implementing RBAC on a type enforced system. In: Proceedings of 13th Annual Computer Security Applications Conference. 1997. 158\u2013163","DOI":"10.1109\/CSAC.1997.646185"},{"key":"28_CR21","doi-asserted-by":"crossref","unstructured":"Chandramouli R. A framework for multiple authorization types in a healthcare application system. In: Proceedings of the 17th Annual Computer Security Application Conference. 2001. 137\u2013148","DOI":"10.1109\/ACSAC.2001.991530"},{"key":"28_CR22","volume-title":"Standards Project, Draft Standard for Information Technology\u2014Portable Operating System Interface (POSIX), PSSG Draft 17","author":"Portable Applications Standards.","year":"1997","unstructured":"Portable Applications Standards. Committee of IEEE Computer Society. Standards Project, Draft Standard for Information Technology\u2014Portable Operating System Interface (POSIX), PSSG Draft 17. New York: IEEE Inc., 1997"},{"issue":"1","key":"28_CR23","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1360\/03yf0244","volume":"48","author":"Q. G. Ji","year":"2005","unstructured":"Ji Q G, Qing S H, He Y P. A new formal model for privilege control with supporting POSIX capability mechanism. Sci China Ser F-Inf Sci, 2005, 48(1): 46\u201366","journal-title":"Sci China Ser F-Inf Sci"},{"issue":"10","key":"28_CR24","doi-asserted-by":"crossref","first-page":"613","DOI":"10.1145\/362375.362389","volume":"16","author":"B. Lampson","year":"1973","unstructured":"Lampson B. A note on the confinement problem. Comm ACM, 1973, 16(10): 613\u2013615","journal-title":"Comm ACM"},{"issue":"6","key":"28_CR25","doi-asserted-by":"crossref","first-page":"569","DOI":"10.1109\/32.55086","volume":"16","author":"C. Tsai","year":"1990","unstructured":"Tsai C, Gligor V, Chandersekaran C. On the identification of covert storage channels in secure systems. IEEE Trans Software Engin, 1990, 16(6): 569\u2013580","journal-title":"IEEE Trans Software Engin"},{"issue":"3","key":"28_CR26","doi-asserted-by":"crossref","first-page":"256","DOI":"10.1145\/357369.357374","volume":"1","author":"R. Kemmerer","year":"1983","unstructured":"Kemmerer R. Shared resource matrix methodology: An approach to identifying storage and timing channels. ACM Trans Comput Syst, 1983, 1(3): 256\u2013277","journal-title":"ACM Trans Comput Syst"},{"issue":"11","key":"28_CR27","doi-asserted-by":"crossref","first-page":"1166","DOI":"10.1109\/32.106972","volume":"17","author":"R. Kemmerer","year":"1991","unstructured":"Kemmerer R. Covert flow trees: A visual approach to analyzing covert storage channels. IEEE Trans Software Engin, 1991, 17(11): 1166\u20131185","journal-title":"IEEE Trans Software Engin"},{"key":"28_CR28","unstructured":"McHugh J, Handbook for the computer security certification of trusted systems \u2014 covert channel analysis. Technical Report, Naval Research Laboratory, Feb. 1996"},{"key":"28_CR29","first-page":"224","volume":"22","author":"R. Kemmerer","year":"1996","unstructured":"Kemmerer R, Taylor T. Modular covert channel analysis methodology for trusted DG\/UX. IEEE Trans Software Engin, 1996, 22: 224\u2013235","journal-title":"IEEE Trans Software Engin"},{"issue":"12","key":"28_CR30","first-page":"1837","volume":"15","author":"S. H. Qing","year":"2004","unstructured":"Qing S H. Covert channel analysis in secure operating systems with high security levels. J Software (in Chinese), 2004, 15(12): 1837\u20131849","journal-title":"J Software (in Chinese)"},{"issue":"9","key":"28_CR31","first-page":"1385","volume":"15","author":"S. H. Qing","year":"2004","unstructured":"Qing S H, Zhu J F. Covet channel analysis on ANSHENG secure operating system. J Software (in Chinese), 2004, 15(9): 1385\u20131392","journal-title":"J Software (in Chinese)"},{"key":"28_CR32","unstructured":"Qing S H, Ji Q G. Formal model design for secure operating system (invited paper). In: Proceedings of ITI First International Conference on Information & Communications Technology (ICICT2003), Egypt, 2003. 27\u201347"}],"container-title":["Science in China Series F: Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-007-0028-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11432-007-0028-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-007-0028-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T15:35:53Z","timestamp":1559403353000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11432-007-0028-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,6]]},"references-count":32,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2007,6]]}},"alternative-id":["28"],"URL":"https:\/\/doi.org\/10.1007\/s11432-007-0028-3","relation":{},"ISSN":["1009-2757","1862-2836"],"issn-type":[{"value":"1009-2757","type":"print"},{"value":"1862-2836","type":"electronic"}],"subject":[],"published":{"date-parts":[[2007,6]]}}}