LATTICE-BASED ACCESS-CONTROL MODELS

被引:240
作者
SANDHU, RS
机构
基金
美国国家科学基金会;
关键词
D O I
10.1109/2.241422
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Lattice-based access control models were developed in the early 1970s to deal with the confidentiality of military information. Security researchers soon realized that these models were useful in many situations where information flow was of concern. Denning's axioms identified the precise circumstances under which these models were applicable. In the late 1970s and early 1980s, researchers applied these models to certain integrity concerns. Recently, application of the models to the Chinese Wall policy, a confidentiality policy unique to the commercial sector, was demonstrated. For the most part, the commercial sector has ignored lattice-based controls, perhaps due to their genesis in military confidentiality policies. At the other extreme, some in the military and government sectors have touted lattice-based controls as a panacea for all information security concerns. This article provides a balanced perspective on lattice-based access control models. The models are presented as a very important ingredient of information security, applicable to confidentiality and integrity concerns in the military and commercial sectors. At the same time, the author identifies the limitations of the models. They are very useful but should not be viewed as a complete solution - even for confidentiality, let alone integrity.
引用
收藏
页码:9 / 19
页数:11
相关论文
共 14 条
[1]  
BELL DE, 1975, M74244 MITR CORP REP
[2]  
BELL DE, AD771543
[3]  
BIBA KJ, 1977, ADA039324
[4]  
Boebert W. E., 1985, 8 NAT COMP SEC C GAI, P18
[5]  
Brewer D. F. C., 1989, P IEEE S SEC PRIV OA, P215
[6]   LATTICE MODEL OF SECURE INFORMATION-FLOW [J].
DENNING, DE .
COMMUNICATIONS OF THE ACM, 1976, 19 (05) :236-243
[7]  
Gougen J., 1982, P S SEC PRIV APR, P11
[8]  
LAMPSON B, 1971, 5 PRINC S INF SCI SY, P437
[9]   CONFINEMENT PROBLEM [J].
LAMPSON, BW .
COMMUNICATIONS OF THE ACM, 1973, 16 (10) :613-615
[10]  
LIPNER S, 1982, 1982 P S SEC PRIV IE, P2