Transaction Processing Using an Untrusted Scheduler in a Multilevel Database with Replicated Architecture
Oliver Costich · 1992
Replicated architecture has been proposed as a way to obtain acceptable performance in a multilevel secure database system. This architecture contains a separate database for each security level such that each contains replicated data from lower security classes. The consistency of the values of replicated data items must be maintained without unnecessarily interfering with concurrency of database operations. This paper provides a protocol to do this that is secure, since it is free of covert channels, and also ensures one-copy serializability of executing transactions. The protocol can be implemented with untrusted processes for both concurrency and recovery. 1. INTRODUCTION In recent history, significant energy has been expended in attempts to develop database systems that protect classified information from unauthorized users based on the classification of the data and the clearances of the users. These are generally referred to as multilevel database systems. * This work was suppo...