Computer Science ›› 2017, Vol. 44 ›› Issue (10): 150-158.doi: 10.11896/j.issn.1002-137X.2017.10.029

Mixed Flow Policy Based On-demand Distributed Cloud Information Flow Control Model

DU Yuan-zhi, DU Xue-hui and YANG Zhi   

  • Online:2018-12-01 Published:2018-12-01

Abstract: In order to protect the security of user information in virtual machine on the cloud platform,this paper proposed a mixed flow control based on-demand distributed information flow control model (MDIFC).This model deve-lopes from DIFC,and the taint propagation is introduced to track the sensitive data so that the system can enforce the strategy and the user data can be protected better.In order to improve the flexibility of the model,considering the initiative of virtual domains,the concept of on-demand controlled and output classification were proposed.The model can reduce the workload result from taint propagation at the same time.This paper introduced its specification using π calculus and proved the security property of noninterference of MDIFC system with PicNic tool.Finally,this paper used an example to demonstrate of MDIFC.

Key words: Cloud computing,Information flow control,On-demand taint propagation,Chinese wall policy,π calculus

