Data Protection and Security |
||||||
V |
Access Control |
|||||
V.V |
Formal Models for Access Control |
|||||
|
The Bell-LaPadula Model It was designed in 1973 in response to US Air Force concerns over the security of time-sharing mainframe systems. By the early 1970's, people had realized that the protection offered by many commercial OS's was poor, and was not getting better. Bell-LaPadula Model (BLP) is a state machine model capturing the confidentiality aspects of access control. The model defines two mandatory access rules:
A formal description of BLP is as follows: S = set of subjectsO = set of objects A = {exec, read, write, append} (access operations) L = set of security levels with partial ordering “=”
The current state a Bell / LaPadula (BLP) system is described by: The following security properties are defined:
|
||||||
|
||||||
|
chapter index | |||||