Protection technology of data processed in distributed information systems
Received 17.06.2021, Revised 06.10.2021, Accepted 19.11.2021, Published 17.12.2021
Abstract
To solve the problem of protecting information from unauthorized access in any information system which is based on control and delimitation of access rights of subjects to protected objects, primarily to file objects designed to store processed data. The implementing access control is to use one of the abstract models like discretionary, mandated and role-based access control. An innovative approach to protecting data processed in distributed information systems through the methods of access control to the objects being created – to the file objects and to the clipboard. Those allow to exclude the access object from the delimiting policies because of automatic markup of created objects. Practical implementation of this approach, provided that the markup (created attributes) directly in the created file allows to identify and solve the problem of implementing the delimiting policy of access to data processed in a distributed information system by considering different ways of data exchange between components of a similar system. This implements data flow management within the system. The considered data protection technology in the information system based on the use of access control methods allows: to get a new property of delimiting access policy in a distributed information system by using different methods of data exchange between components/computers; to increase the efficiency of the information security system by managing data flows in the system.
Keywords:
distributed information system; data protection; unauthorized access; control and delimitation of access rights; delimiting policy; object created; data flow management