Lecture 5: April 8, 2026
Reading:
text
, §2, 4.1–4.4
Assignments:
Homework 1, due April 10, 2026
Greetings and felicitations!
Access Control Matrix
Commands and conditions: create•{}file, various flavors of grant•{}right to show conditions and nested commands
Copy flag, own rights
Principle of attenuation of privilege
Decidability of security
Notion of leakage in terms of ACM
Determining security of a generic system with generic rights and mono-operational commands is decidable
Determining security of a generic system with generic rights is undecidable (HRU result)
Meaning: can’t derive a generic algorithm; must look at (sets of) individual case
Policy
Sets of authorized, unauthorized states
Secure systems in terms of states
Mechanism vs. policy
Types of Policies
Military/government vs. confidentiality
Commercial vs. integrity
Trust
Matt Bishop
Office: 2209 Watershed Sciences
Phone: +1 (530) 752-8060
Email:
mabishop@ucdavis.edu
ECS 153A, Computer & Information Security & Privacy I
Version of April 8, 2026 at 3:53PM
You can also obtain a PDF version of this.