Information Flow Control in Software DB Units Based on Formal Verification

A. А. Timakov · Programming and Computer Software · 2022

Abstract By now, a large number of studies in the field of formal models of computer systems security have been performed. In this paper, we do not consider cryptographic methods of information protection, which, as applied to information systems, ensure security of data storage and transfer. The focus in this paper is on the models based on access control and information flow control that ensure security of data processing. The models based on access control are widely used for implementing protection mechanisms at the level of operating systems (OS) and database management systems (DBMS). Information flow control (IFC) is presently integrated into language platforms designed for creating both system and application software. However, despite all efforts, the dominating approach in the practical design of automated industry-level information systems is exclusively directed to the implementation of system-wide mechanisms of access control. The IFC at the level of applications is often considered without taking into account the requirements of global security policy. In this paper, an attempt is made to justify the necessity of complementing the global access control systems in software with IFC. An algorithm for integrating the IFC at the level of database program units on the basis of the role-based access control implemented at the system level is described.

Read the paper · More papers on PaperTik