Evaluation of the Trust Zone Model with the Information Flow Control
摘要
A ZT model is proposed and discussed these days. Here, since it is assumed that all the accesses are not trustworthy, every access can be allowed is checked. Hence, the ZT model is regarded as the method to protect networks of enterprises from any threats. Since it is critical to make the shift from the present system model to the ZT model smooth, a TZ (Trust Zone) model is proposed. Here, every object is in a trust zone and an authorization decision is made for each trust zone. However, prevention of the illegal information flow is not discussed in the TZ model. In our previous studies, a TZMAC (Trust Zone with Mandatory Access Control) model is proposed. Here, not only objects but also subjects belong to trust zones. Access rules are given based on the relation between the trust zones of the subject and object so that the illegal information flow does not occur. We evaluate the TZMAC model compared with the TZ model in this paper. In both models, operations which do not follow each access rule are rejected to protect the networks from illegal accesses. Evaluation results show that there are operations rejected but illegal information flow occurs in the TZ model. Although the number of operations rejected in the TZMAC model is larger than the TZ model, illegal information flow does not occur.