Lecture 13: April 26, 2021
Reading: text, §5.3, 6.1–6.2, 6.4
Due: Lab 2, due May 5, 2021; Homework 3, due May 7, 2021
- Tranquility
- Declassification problem
- Strong tranquility
- Weak tranquility
- Requirements of integrity models
- Biba Model (strict integrity policy)
- Clark-Wilson Model
- Theme: military model does not provide enough controls for commercial fraud, etc. because it does not cover the right aspects of integrity
- Components
- Constrained Data Items (CDI) to which the model applies
- Unconstrained Data Items (UDIs) to which no integrity checks are applied
- Integrity Verification Procedures (IVP) that verify conformance to the integrity spec when IVP is run
- Transaction Procedures (TP) takes system from one well-formed state to another