首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >Correctness criteria for multilevel secure transactions
【24h】

Correctness criteria for multilevel secure transactions

机译:多级安全交易的正确性标准

获取原文
获取原文并翻译 | 示例

摘要

The benefits of distributed systems and shared database resources are widely recognized, but they often cannot be exploited by users who must protect their data by using label-based access controls. In particular, users of label-based data need to read and write data at different security levels within a single database transaction, which is not currently possible without violating multilevel security constraints. The paper presents a formal model of multilevel transactions which provide this capability. We define four ACIS (atomicity, consistency, isolation, and security) correctness properties of multilevel transactions. While atomicity, consistency and isolation are mutually achievable in standard single-site and distributed transactions, we show that the security requirements of multilevel transactions conflict with some of these goals. This forces trade-offs to be made among the ACIS correctness properties, and we define appropriate partial correctness properties. Due to such trade-offs, an important problem is to design multilevel transaction execution protocols which achieve the greatest possible degree of correctness. These protocols must provide a variety of approaches to making trade-offs according to the differing priorities of various users. We present three transaction execution protocols which achieve a high degree of correctness. These protocols exemplify the correctness trade-offs proven in the paper, and offer realistic implementation options.
机译:分布式系统和共享数据库资源的好处已得到广泛认可,但是必须使用基于标签的访问控制来保护其数据的用户通常无法利用它们。特别是,基于标签的数据的用户需要在单个数据库事务中以不同的安全级别读取和写入数据,而这在不违反多级安全约束的情况下当前是不可能的。本文提出了提供此功能的多层交易的正式模型。我们定义了多级事务的四个ACIS(原子性,一致性,隔离性和安全性)正确性属性。虽然在标准的单站点和分布式事务中可以同时实现原子性,一致性和隔离性,但是我们证明了多层事务的安全性要求与其中一些目标相冲突。这迫使必须在ACIS正确性属性之间进行权衡,并且我们定义适当的部分正确性属性。由于这种折衷,一个重要的问题是设计能够实现最大程度的正确性的多级事务执行协议。这些协议必须提供各种方法,以根据不同用户的不同优先级进行权衡。我们提出了三种实现高度正确性的事务执行协议。这些协议例证了本文中证明的正确性折衷,并提供了现实的实现选项。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号