Achieving Database Security through Data Replication: the Sintra Prototype
نویسندگان
چکیده
There are several proposed approaches for multilevel secure (MLS) database systems which protect classi ed information. The SINTRA database system, which is currently being prototyped at the Naval Research Laboratory, is a multilevel trusted database system based on a replicated data approach. This approach uses physical separation of classi ed data as a protection measure. Each database contains data at a given security level and replicas of all data at lower security levels. Project goals include good performance and full database capability. For practical reasons (e.g., ease of evaluation, portability) the SINTRA database system uses as many readily-available commercial components as possible. In this paper, security constraints and the rationale for the SINTRA prototype are described. We also present the structure and function of each component of the SINTRA prototype: the global scheduler, the query preprocessor, and the user interface. A brief description of the SINTRA recovery mechanism is also presented.
منابع مشابه
Confidentiality in a Replicated Architecture Trusted Database System: A Formal Model
Unlike previous approaches to developing a trusted database system, the replicated architecture approach provides access control at a high level of assurance through replication of data and operations. We present a model of the SINTRA replicated architecture trusted database system which shows how the logical (users') view of the system and its security policy is translated into the physical st...
متن کاملSecure Intrusion-tolerant Replication on the Internet
This paper describes a Secure INtrusion-Tolerant Replication Architecture1 (SINTRA) for coordination in asynchronous networks subject to Byzantine faults. SINTRA supplies a number of group communication primitives, such as binary and multi-valued Byzantine agreement, reliable and consistent broadcast, and an atomic broadcast channel. Atomic broadcast immediately provides secure statemachine rep...
متن کاملArchitectural Impact on Performanceof a Multilevel Database
Since protection and assurance are the primary concerns in MLS databases, performance has often been sacriiced in some known MLS database approaches. Motivated by performance concerns, a replicated architecture approach which uses a physically distinct backend database management system for each security level is being investigated. This is a report on the behavior and performance issues for th...
متن کاملAn Efficient Data Replication Strategy in Large-Scale Data Grid Environments Based on Availability and Popularity
The data grid technology, which uses the scale of the Internet to solve storage limitation for the huge amount of data, has become one of the hot research topics. Recently, data replication strategies have been widely employed in distributed environment to copy frequently accessed data in suitable sites. The primary purposes are shortening distance of file transmission and achieving files from ...
متن کاملArchitectural impact on performance of a multilevel database system
Since protection and assurance are the primary concerns in MLS databases, performance has often been sacri ced in some known MLS database approaches. Motivated by performance concerns, a replicated architecture approach which uses a physically distinct backend database management system for each security level is being investigated. This is a report on the behavior and performance issues for th...
متن کامل