Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
A comment on the ‘basic security theorem’ of Bell and LaPadula
McLean J. Information Processing Letters20 (2):67-70,1985.Type:Article
Date Reviewed: Dec 1 1985

This paper presents a clarification of the role that the Basic Security Theorem (BST) of Bell and LaPadula plays in the security model developed by those authors [1]. The major point made is that this role is essentially independent of notions of security. The BST gives conditions by which a system is secure, based on a definition of a secure state. The author shows that the proof of the BST can be carried out for any definition of secure state that permits indexing of states and an inductive proof. Consequently, the BST itself gives no assurance of security beyond the basic definition of secure state.

The author’s objective is to make clear that the proof of the BST does not enhance the definition of secure state and that work in security should address the basic problems of formalizing notions of security rather than reproving the BST for new models. The author acknowledges that, although some others have, Bell and LaPadula did not ascribe more significance to the BST than is warranted.

Reviewer:  Glenn H. MacEwen Review #: CR109618
1) Bell, D. E.; and LaPadula, I. J.Secure computer system: unified exposition and multics interpretation, MITRE, MTR-2997, 1976; available as NTIS AD-A023 588.
Bookmark and Share
 
Security and Protection (D.4.6 )
 
 
Military (J.1 ... )
 
 
Data Encryption (E.3 )
 
Would you recommend this review?
yes
no
Other reviews under "Security and Protection": Date
Practical UNIX security
Garfinkel S., Spafford G., O’Reilly & Associates, Inc., Sebastopol, CA, 1991. Type: Book (9780937175729)
Jun 1 1992
Trusted products evaluation
Chokhani S. Communications of the ACM 35(7): 64-76, 1992. Type: Article
Oct 1 1993
An experience using two covert channel analysis techniques on a real system design
Haigh J., Kemmerer R., McHugh J., Young W. IEEE Transactions on Software Engineering SE-13(2): 157-168, 1987. Type: Article
Nov 1 1987
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy