LBAC Web

Ying Yang, Zheng Song · 2019

The e-government puts forward the growing security demands on information system, in this context, thin client based solution appears. The thin client provides similar functions but better security by cloud storage and centralized management as rich client. The main technologies are virtual desktop infrastructure (VDI) and Web client by now. Recently the development of Web-based operating system (Web OS) promotes Web client. But these Web OSes mainly aim at mobility and cross-platform, give less confidentiality and integrity support for e-government. Firstly, this paper analyzes four open source Web OSes on their application type, access control policies and their security problems. Then it abstracts the common security model of Web OSes. Secondly, based on this common security model, it constructs a LBACWeb (Lattice-based access control model for Web OS) model, which combining confidential label, integrity label and category set on the basis of lattice structure. Finally, it proposes the least privilege principle on trusted subjects and define a special privileged subject to enhance the flexibility and usability. The analysis and verification are given at last to elaborate the security and applicability of the LBACWeb model.

Read the paper · More papers on PaperTik