Unified Security Model for Computer System Component Interactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-level security models, such as Bell-LaPadula and Biba, are restrictive and inflexible, failing to effectively balance data confidentiality and integrity, leading to potential security compromises when attempting to implement both in practical systems.
Innovation Solution
A method is introduced where each component in a computer system is assigned a fixed security level, and interactions between components are monitored and controlled based on these levels, prohibiting interactions that exceed a single security level difference, with priority levels used to assess and potentially lift status block conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Bell-LaPadula model is implemented to ensure data confidentiality, then data confidentiality is improved, but data integrity control is worsened
Solution Approach 1:
The patent combines Bell-LaPadula (confidentiality) and Biba (integrity) models into a unified security framework. The system simultaneously enforces both read-up/write-down restrictions (confidentiality) and read-down/write-up restrictions (integrity) by evaluating security levels of subjects and objects for both confidentiality and integrity, allowing both security goals to be achieved without compromise
Solution Approach 2:
The patent introduces dual security level parameters (confidentiality level and integrity level) for each subject and object, rather than using a single security level. This parameter expansion allows the system to independently control confidentiality and integrity aspects, resolving the contradiction between the two security objectives
2Reliability
If Biba model is implemented to ensure data integrity, then data integrity is improved, but data confidentiality control is worsened
Solution Approach 1:
The patent merges Bell-LaPadula and Biba models into a unified framework that simultaneously enforces both confidentiality and integrity controls. By evaluating both confidentiality levels and integrity levels separately for each subject-object interaction, the system achieves comprehensive security coverage without sacrificing either confidentiality or integrity
Solution Approach 2:
The system uses dual-parameter security levels (confidentiality and integrity) to independently control access restrictions. This allows the system to enforce both read-up/write-down (confidentiality) and read-down/write-up (integrity) rules simultaneously, resolving the limitation of the standalone Biba model
3Reliability
If strict multi-level security models are implemented, then security control is improved, but system flexibility is worsened
Solution Approach 1:
The patent introduces dynamic status blocks that can be temporarily imposed and subsequently lifted based on priority assessments. When a status block is imposed due to security level differences, the system can evaluate priority levels of competing interactions and lift the block for higher-priority interactions, providing dynamic adaptability while maintaining security control
Solution Approach 2:
The system segments security control into multiple independent evaluation dimensions (confidentiality level, integrity level, status block status, priority level). Each dimension can be independently assessed and controlled, allowing fine-grained security management that maintains flexibility through modular decision-making
4Reliability
If security levels are increased to minimize risk, then security is improved, but system partitioning is worsened
Solution Approach 1:
The patent applies different security level assignments to different subjects and objects based on their specific roles and data access requirements. Rather than uniformly assigning top security levels to all components, the system locally optimizes security levels for each subject-object pair, maintaining security while avoiding unnecessary system-wide partitioning
Data Source
AI summary
The embodiments of the present invention relate to controlling interactions between one or more components of a computer system, where each component is assigned a fixed security level and all currently active and newly requested interactions between components of the system are monitored.


