Outline for April 13, 2004
- Expressive power
- HRU vs. SPM
- Multiparent joint creates in HRU
- Adding multiparent joint creates to SPM (giving ESPM)
- Simulation of multiparent joint creates by 2-parent joint creates
- Monotonic ESPM, monotonic HRU equivalent
- Safety question in ESPM decidable if acyclic attenuating scheme
- Comparing Expressive Power of Models
- Graph representation
- Go through 3-parent joint create as simulated by 2-parent joint
create
- Correspondence between two schemes in terms of graph representation
- Formal definition of scheme A simulating scheme B
- Model expressive power
- Result: monotonic 1-parent models less expressive than monotonic
multiparent models (so ESPM more expressive than SPM)
- Typed Access Matrix Model
- Add notion of type for entities--set of types T, set of
subject types TS ⊆ T
- New create rules: specify subject/object type
- In command, child type if something of that type created;
otherwise, a parent type
- Show type graph and cycles in it
- Safety decidable for systems with acyclic MTAM schemes
- Policy
- Define security policy, secure system, breach
of security formally
- Security models
- Confidentiality, integrity policies; distinguish from military,
commercial policies
- Role of trust in modeling
- DAC vs. MAC vs. ORCON
Here is a PDF version of this document.