An introduction to multilevel secure relational database management systems
نویسنده
چکیده
Multilevel Security (MLS) is a capability that allows information with different classifications to be available in an information system, with users having different security clearances and authorizations, while preventing users from accessing information for which they are not cleared or authorized. It is a security policy that has grown out of research and development efforts funded mostly by the U.S. Department of Defense (DoD) to address some of the drawbacks of the single level mode of operation that was used at the DoD. The goal was to build and deploy an MLS-compliant environment (e.g., Networks, Operating Systems, Database Systems) that would provide a much needed efficiency in processing and distributing classified information by providing security through computer security, communications security, and trusted system techniques instead of using physical controls, administrative procedures, and personnel security. As Relational Database Management Systems (RDBMS) are at the heart of the DoD’s information system, significant research and development efforts have been put into building multilevel secure RDBMS, which have led to the emergence Copyright c © 2004 IBM Canada Ltd., 2004. Permission to copy is hereby granted provided the original copyright notice is reproduced in copies made. of a number of multilevel secure RDBMS solutions, including commercial ones. Over the past few years and with the increase of security concerns, MLS compliance has become a major requirement from a number U.S. Federal Government agencies that appear to have grown beyond the traditional agencies that require such type and level of security. This paper introduces MLS, and outlines the challenges and complexities of building a multilevel secure RDBMS. The paper also gives concrete examples of both research and commercial multilevel secure RDBMS and describes how they met the above challenges and complexities.
منابع مشابه
Toward a Multilevel Secure Relational
Although there are several eeorts underway to build multilevel secure relational database management systems , there is no clear consensus regarding what a multilevel secure relational data model exactly is. In part this lack of consensus on fundamental issues re-ects the subtleties involved in extending the classical (single-level) relational model to a multilevel environment. Our aim in this ...
متن کاملToward a Multilevel Secure Re- lational Data Model
Although there are several e orts underway to build multilevel secure relational database management systems, there is no clear consensus regarding what a multilevel secure relational data model exactly is. In part this lack of consensus on fundamental issues reects the subtleties involved in extending the classical (single-level) relational model to a multilevel environment. Our aim in this pa...
متن کاملSecurity Constraint Processing in a Multilevel Secure Distributed Database Management System
In a multilevel secure distributed database management system, users cleared at different security levels access and share a distributed database consisting of data at different sensitivity levels. An approach to assigning sensitivity levels, also called security levels, to data is one which utilizes constraints or classification rules. Security constraints provide an effective classification p...
متن کاملSecurity issues for federated database systems
This paper describes security issues for federated database management systems set up for managing distributed, heterogeneous and autonomous multilevel databases. It builds on our previous work in multilevel secure distributed database management systems and on the results of others’ work in federated database systems. In particular, we define a multilevel secure federated database system and d...
متن کاملTowards the Design and Implementation of a Multilevel Secure Deductive Database Management System
In this paper we describe a preliminary design and implementation of a multilevel secure deductive database management system (MLSIDEDBMS). In particular, logic as a dara model for multilevel databases, reasoning across security levels, architectural issues for an MLSIDEDBMS, and a prototype implementation are discussed.
متن کامل