Lecture 7: April 13, 2026
Reading:
text
, §5.3, 6.1–6.2, 6.4
Assignments:
Homework 2, due April 24, 2026
Greetings and felicitations!
Example: Trusted Solaris
Tranquility
Declassification problem
Strong tranquility
Weak tranquility
Requirements of integrity models
Biba Model (strict integrity policy)
Clark-Wilson Model
Theme: military model does not provide enough controls for commercial fraud, etc. because it does not cover the right aspects of integrity
Components
Constrained Data Items (CDI) to which the model applies
Unconstrained Data Items (UDIs) to which no integrity checks are applied
Integrity Verification Procedures (IVP) that verify conformance to the integrity spec when IVP is run
Transaction Procedures (TP) takes system from one well-formed state to another
Matt Bishop
Office: 2209 Watershed Sciences
Phone: +1 (530) 752-8060
Email:
mabishop@ucdavis.edu
ECS 153A, Computer & Information Security & Privacy I
Version of April 12, 2026 at 3:06PM
You can also obtain a PDF version of this.