Granularity of Data Protection for MLS Applications and DBMSs
Arnon S. Rosenthal, William R. Herndon · 1993
This paper examines the tradeoffs inherent in designing a practical multilevel secure (MLS) DBMS with object management capabilities. In the near future, builders of applications with complex structures, such as design or multimedia systems, will routinely use This work was funded under contract DAAB07-93-C-N651 from SPAWAR OOI. object DBMSs. Therefore, secure object DBMSs will be needed to support such applications operating in an MLS environment. Assuming that security and assurance requirements have been met, we believe that these systems should be judged principally on how good an environment they provide for application development and evolution, with application performance also a significant factor. We therefore analyze the convenience of developing single-level applications over MLS data, and the performance of hypothetical S-DBMSs under various assumptions about the granularity of protection and DBMS architecture. The analysis in this paper leads to two main conclusions: . Applications should be written over an interface consisting of multi-level conceptual objects that match real world or mental phenomena. A conceptual object may include attributes at different security levels, and its class definition is independent of security level assignments. . It is desirable and feasible to build a secure DBMS that directly supports multilevel conceptual objects, supplying their storage and access operations. If scoped appropriately (section 3.1.1), the support need not be excessively complex or costly. Support for conceptual objects as derived data (i.e., as views) is shown to be somewhat less advantageous. We reason from the application developer's point of view, as well as the DBMS builder's. To support our first conclusion, we argue that application code is simpl...