April 21: Bell-LaPadula Model
- Bell-LaPadula confidentiality model
- Tranquility
- Declassification
- McLean’s criticism and System Z
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #1
April 21: Bell-LaPadula Model Bell-LaPadula confidentiality model - - PowerPoint PPT Presentation
April 21: Bell-LaPadula Model Bell-LaPadula confidentiality model Tranquility Declassification McLeans criticism and System Z April 21, 2017 ECS 235B Spring Quarter 2017 Slide #1 Rule : R V D V Takes a
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #1
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #2
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #3
simple security condition; then choose t ∈ N such that (xt, yt, zt) is first appearance not meeting simple security condition
ρ(xt, zt–1) = (yt, zt) and yt ≠ i.
then zt meets simple security condition, contradiction.
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #4
– Proof
satisfying ssc rel f
converse, (s, o, p) ∈ bʹ satisfies ssc rel f, so vʹ satisfies simple security condition
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #5
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #6
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #7
1. If bʹ ⊆ b, fʹ = f, and v satisfies the simple security condition, then vʹ satisfies the simple security condition 2. If bʹ ⊆ b, fʹ = f, and v satisfies the *-property, then vʹ satisfies the *-property 3. If bʹ ⊆ b, m[s, o] ⊆ mʹ [s, o] for all s ∈ S and o ∈ O, and v satisfies the ds-property, then vʹ satisfies the ds-property
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #8
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #9
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #10
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #11
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #12
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #13
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #14
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #15
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #16
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #17
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #18
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #19
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #20
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #21
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #22
– s1 gives (request to give) s2 the (discretionary) right to read o – Rule: can be done if giver can alter parent of object
– root(o): root object of hierarchy h containing o – parent(o): parent of o in h (so o ∈ h(parent(o))) – canallow(s, o, v): s specially authorized to grant access when
– m∧m[s, o]←r: access control matrix m with r added to m[s, o]
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #23
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #24
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #25
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #26
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #27
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #28
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #29
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #30
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #31
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #32
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #33
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #34
– For *-property, it’s “object dominates subject”
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #35
– Every (s, o, p) ∈ bʹ – b satisfies the †-property relative to Sʹ – Every (s, o, p) ∈ b that does not satisfy the †-property relative to Sʹ is not in b
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #36
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #37
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #38
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #39
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #40
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #41
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #42
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #43
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #44
April 21, 2017 ECS 235B Spring Quarter 2017 Slide #45