Bell and LaPadula axioms
T. Lin · 1993
Ideally secure systems must, be provable secure, so they are all defined by mathematical models. Most of current systems are based on the Bell and LaPadula Model (BLM), however, many usages are not logically sound. In this paper, a new paradigm is proposed to reinterpret the BLM. BLM is treated as axioms to define the multilevel security, in the same spirit as Hilbert axioms to the Euc1idean geometry. Absolutely no violations are tolerated. So many usual trusted subjects are no longer admissible in this new BLM. Three layer architecture is proposed to accommodate such requirements.