Multilevel Secure Database Management Prototypes

نویسنده

  • Thomas H. Hinke
چکیده

The three systems described in this essay each target the most stringent security standards embodied in the A1 requirements as defined by the US Department of Defense " Trusted Computer Systems Evaluation Criteria " [DOD85], which is commonly called the Orange Book. While the initial designs of all these systems — and in some cases the implementations — predate the " Trusted Database Management System Interpretation of the Trusted Computer System Evaluation Criteria " [NCSC91] (commonly called the TDI), they all had the Orange Book as a guide to the fundamental requirements that must be satisfied by a secure system at the A1 level. Also, in some cases, work on these prototypes provided the basis for comments on the evolving TDI. In addition to their A1 target, these three systems share a similarity in that they were and are intended as research prototypes, not commercial products. This means that they are not held to the requirement of satisfying market conditions, but also that they may not have had the funding to include all of the capabilities that would be required of a commercial offering. Their intent was to push forward the frontier in the area of security, but not necessarily with all the " bells and whistles " of a complete product. This is not to detract from their contributions, which are many, but only to alert the reader to the fact that today's research prototype may lead tomorrow's commercial product by many years. All of the systems enforce both a mandatory and a discretionary policy. The basis for mandatory enforcement is the access class, which includes a hierarchical, linearly ordered component called levels (for example , Top Secret > Secret > Confidential > Unclassified), and a nonhierarchical component called categories, which is not ordered. The set of access classes is partially ordered and forms a lattice. In this lattice , access class A is said to dominate access class B if the hierarchical component of A is greater than or equal to the hierarchical component of B, and the set of categories associated with A is a superset of the set

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Multilevel security issues in distributed database management systems II

The rapid growth of the networking and information-processing industries has led to the development of distributed database management system prototypes and commercial distributed database management systems. In such a system, the database is stored in several computers which are interconnected by some communication media. The aim of a distributed database management system (DDBMS) is to proces...

متن کامل

Toward a Multilevel Secure Relational

Although there are several eeorts underway to build multilevel secure relational database management systems , there is no clear consensus regarding what a multilevel secure relational data model exactly is. In part this lack of consensus on fundamental issues re-ects the subtleties involved in extending the classical (single-level) relational model to a multilevel environment. Our aim in this ...

متن کامل

Security Constraint Processing in a Multilevel Secure Distributed Database Management System

In a multilevel secure distributed database management system, users cleared at different security levels access and share a distributed database consisting of data at different sensitivity levels. An approach to assigning sensitivity levels, also called security levels, to data is one which utilizes constraints or classification rules. Security constraints provide an effective classification p...

متن کامل

Towards the Design and Implementation of a Multilevel Secure Deductive Database Management System

In this paper we describe a preliminary design and implementation of a multilevel secure deductive database management system (MLSIDEDBMS). In particular, logic as a dara model for multilevel databases, reasoning across security levels, architectural issues for an MLSIDEDBMS, and a prototype implementation are discussed.

متن کامل

Security issues for federated database systems

This paper describes security issues for federated database management systems set up for managing distributed, heterogeneous and autonomous multilevel databases. It builds on our previous work in multilevel secure distributed database management systems and on the results of others’ work in federated database systems. In particular, we define a multilevel secure federated database system and d...

متن کامل

Toward a Multilevel Secure Re- lational Data Model

Although there are several e orts underway to build multilevel secure relational database management systems, there is no clear consensus regarding what a multilevel secure relational data model exactly is. In part this lack of consensus on fundamental issues reects the subtleties involved in extending the classical (single-level) relational model to a multilevel environment. Our aim in this pa...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006