The modeling and representation of security semantics for database applications
Gary W. Smith · 1990
The rapid change of technology over the last decade created new vulnerabilities for computers and telecommunication systems. In response to these vulnerabilities, the computer community accomplished significant research on how to evaluate the security of systems, especially operating systems. The goal was multilevel security--a system where objects (e.g., files) have different classifications, subjects (e.g., users) have a range of clearances, and the system enforces the proper separation. More recently, researchers extended the concepts of multilevel to database systems. These efforts concentrate on secrecy issues but do not address in detail the semantic-level requirements for multilevel database systems (i.e., the data secrecy semantics). Nor have they given the other two components of computer security, integrity and availability, adequate attention. While the computer community concentrates on secrecy, the database community addresses data integrity. They understand the need for the explicit representation of the integrity semantics for database applications and have developed semantic data models for that purpose and to assist in database design. This dissertation provides an approach for representing and modeling the semantics (i.e., secrecy and integrity semantics) for an application domain. A taxonomy of security-relevant knowledge describes the categories of knowledge that must be identified to implement a multilevel secure application system. The taxonomies of data integrity semantics, data secrecy semantics, and access control requirements are a statement of requirements multilevel database systems must support. Specification of the semantics at this level of detail is essential for the analysis of the requirements and the database designs for inference and signaling channels. The Semantic Data Model for Security (SDMS) is presented as a modeling technique for security-relevant data semantics. SDMS has two levels of representation. The top level includes a graphical technique for representing database schema and a constraint language for expressing explicit constraints. It is intended to assist domain experts, officers and database designers in understanding and analyzing their requirements. The lower level is a first-order logic representation of the inherent constraints of the schema and the explicit constraints. It will facilitate automated vulnerabilities analysis. A Multilevel Database Security Specification defines comprehensive requirements for a nontrivial application domain. It incorporates all required data integrity semantics, data secrecy semantics and access controls.