Prikladnaya Diskretnaya Matematika
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive
Impact factor

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Prikl. Diskr. Mat.:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Prikladnaya Diskretnaya Matematika, 2018, Number 39, Pages 42–57
DOI: https://doi.org/10.17223/20710410/39/4
(Mi pdm611)
 

This article is cited in 3 scientific papers (total in 3 papers)

Mathematical Foundations of Computer Security

Multilevel thematic-hierarchical access control (MLTHS-system)

N. A. Gaydamakin

Ural Federal University, Ekaterinburg, Russia
References:
Abstract: Access control in computer systems is based on the combination of confidence-mandatory and thematic principles. Composite security labels (tags) containing a security level (classification grade for objects and access level for subjects) and a thematic index (object themes and thematic permissions for subjects) are assigned to the access objects and subjects. In contrast to the known MLS-model that uses so called non-hierarchical (i.e. unordered) thematic categories in the form of thematic rubrics, our model (MLTS-system) uses thematic object indexes and thematic subject permissions which appear as hierarchical thematic classifier elements widely used in document storage technologies. Mathematically, the security labels are elements of the product of the security level algebraic lattice used in Bell–LaPadula model and of a special multirubric lattice based on hierarchical classifiers. Special dominance relations (wider–narrower) and binary operations (greatest lower and least upper multirubric bounds) that cannot be expressed by using ordinary set-theoretic inclusion relation and union and intersection operations are introduced. In MLTHS-system, for assigning security tags to users and to user-initiated subjects, some specific procedures are defined. Authorization rules to subject-to-object read, write and execute access are defined for security monitor as well as security tag assignment procedures for newly created objects. Multiple access (a single subject to many objects and many subjects to a single object) authorization rules are established. It is proven that MLTHS-system is secure by criteria of flow absence between security tag-incomparable entities (objects or subjects) and of top down flow absence. MLTHS-system allows combining access control and document storage text search technologies to create secure search engines with no functional limitations.
Keywords: access control (management), security model, hierarchical thematic classifier, multirubric, multirubric lattice, documentary information retrieval systems, thematic indexing, MLS-model.
Bibliographic databases:
Document Type: Article
UDC: 004.94
Language: Russian
Citation: N. A. Gaydamakin, “Multilevel thematic-hierarchical access control (MLTHS-system)”, Prikl. Diskr. Mat., 2018, no. 39, 42–57
Citation in format AMSBIB
\Bibitem{Gai18}
\by N.~A.~Gaydamakin
\paper Multilevel thematic-hierarchical access control (MLTHS-system)
\jour Prikl. Diskr. Mat.
\yr 2018
\issue 39
\pages 42--57
\mathnet{http://mi.mathnet.ru/pdm611}
\crossref{https://doi.org/10.17223/20710410/39/4}
\elib{https://elibrary.ru/item.asp?id=32724374}
Linking options:
  • https://www.mathnet.ru/eng/pdm611
  • https://www.mathnet.ru/eng/pdm/y2018/i1/p42
  • This publication is cited in the following 3 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Прикладная дискретная математика
    Statistics & downloads:
    Abstract page:359
    Full-text PDF :248
    References:30
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024