A shift in security modeling paradigms
James Gordon Williams · 1993
Models of the external system interface of a computer have been successfully used to describe confidentiality requirements. This paper discusses the use of an external-interfa,ce model t1la.t supports the external consistency objective of Cla.rk and \\,+Ylson as well as internal structura.1 constra.int,s needed t,o meet identified externa.l-int.erface requirementSs. These internal constraints identify a. vendor-supplied “Integrity Trusted Computing Base” tl1a.t handles informal proofs called “pedigrees.” The increa.sing use of external-interface models, which this work illust,ra.tes, represents a paradigm shift in t#he construction of security models.