Query processing in multilevel secure database systems

Brajendra Panda, William Perrizo · 1993

For the past few years, research in multilevel secure database systems has received a great deal of attention. Such systems are quite essential in military as well as many commercial applications where data are classified according to their sensitivity and where each user has a clearance level. Users access the data as per the system's security policy. A system is most secure if it guards against an unauthorized flow of information either directly or indirectly. In this research, the issue of query processing that takes place among the various base relations in a kernelized multilevel secure database system was analyzed. Specifically, the SeaView model, a research prototype developed as a joint effort by SRI International and Gemini Computer, was followed since it is the only model that uses element level (i.e., the finest granularity level) classification of data. Although the SeaView model aims at achieving class A1 system classification, it has two major drawbacks. First, the query response time is high, due to the large number of outer join operations performed during the reconstruction of multilevel relations. Second, the reconstruction process results in some spurious tuples that provide misleading information to users having higher clearances, which is rather dangerous since decision-making at higher levels plays a crucial role in every application. In this research, a model called Protected Information System Manager, or PRISM in short, was developed. Different security parameters, the access control policies, the multilevel relation, different integrity constraints, and the decomposition and reconstruction algorithms in multilevel relations were designed. For the recovery process, the domain vector accelerator technique was utilized. It has been shown that by using the domain vector accelerator mechanism, a significant performance improvement is achieved over the SeaView model. At the same time, this protocol avoids the generation of spurious tuples, giving the users a correct and fast result. In addition, a concurrency control protocol on the PRISM was proposed in this work. Finally, an integrated mechanism for both concurrency control and query processing was presented in order to preserve the concurrent execution of transactions at all levels while improving their response time.

Read the paper · More papers on PaperTik