A New Mandatory Security Policy Combining Secrecy and Integrity

This paper describes a new mandatory security model that better combines secrecy and commercial data integrity requirements than previous models based on Bell and LaPadula and Biba. The new model solves many of the previously perceived drawbacks and limitations of the Biba model, and makes use of a modified-Biba lattice to incorporate into the model the operation of so-called trusted processes that in the past have always been viewed as annoying exceptions to the existing mandatory security models. It then applies this new model as a better approach to security of mobile code.

Keywords: Mandatory access control, Lattice security models, Biba Integrity model, Bell and LaPadula model, mobile code security.

By: Paul A. Karger, Vernon R. Austel, David C. Toll

Published in: RC21717 in 2000

LIMITED DISTRIBUTION NOTICE:

This Research Report is available. This report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g., payment of royalties). I have read and understand this notice and am a member of the scientific community outside or inside of IBM seeking a single copy only.

RC21717.pdf

Questions about this service can be mailed to reports@us.ibm.com .