A security model for military message systems
- 1 August 1984
- journal article
- Published by Association for Computing Machinery (ACM) in ACM Transactions on Computer Systems
- Vol. 2 (3), 198-222
- https://doi.org/10.1145/989.991
Abstract
Military systems that process classified information must operate in a secure manner; i.e., they must adequately protect information against unauthorized disclosure, modification, and withholding. A goal of current research in computer security is to facilitate the construction of multilevel secure systems, systems that protect information of different classifications from users with different clearances. Security models are used to define the concept of security embodied by a computer system. A single model, called the Bell and LaPadula model, has dominated recent efforts to build secure systems but has deficiencies. We are developing a new approach to defining security models based on the idea that a security model should be derived from a specific application. To evalu- ate our approach, we have formulated a security model for a family of military message systems. This paper introduces the message system application, describes the problems of using the Bell-LaPadula model in real applications, and presents our security model both informally and formally. Significant aspects of the security model are its definition of multi-level objects and its inclusion of application-dependent security assertions. Pro- totypes based on this model are being developed.Keywords
This publication has 8 references indexed in Scilit:
- A comment on the ‘basic security theorem’ of Bell and LaPadulaInformation Processing Letters, 1985
- The use of quick prototypes in the secure military message systems projectACM SIGSOFT Software Engineering Notes, 1982
- Formal Models for Computer SecurityACM Computing Surveys, 1981
- Military Message Systems: Current Status and Future DirectionsIEEE Transactions on Communications, 1980
- A model for verification of data security in operating systemsCommunications of the ACM, 1978
- Information transmission in computational systemsPublished by Association for Computing Machinery (ACM) ,1977
- Proving multilevel security of a system designPublished by Association for Computing Machinery (ACM) ,1977
- A lattice model of secure information flowCommunications of the ACM, 1976