192
Maria Luisa Damiani and Elisa Bertino
its roots in academic and commercial research laboratories; the RBAC model, since
the seminal paper of [23], has gained increasingly consensus in the research community as well as in industry to finally become a standard widely adopted by
organizations [13].
Mandatory Access Control
Mandatory access control models control accesses on the basis of a predefined classification of subjects and objects in the system. Objects are the passive entities storing
information, such as relations in a DBMS. Subjects are active entities performing
data accesses. The classification is based on a number of access classes, also called
labels which are associated with every subject and object in the system. A subject is
granted authorization to access a given object if and only if some relationship, depending on the access mode, is satisfied between the classifications of the subject and
the object. An access class generally consists of two components: a security level and
a set of categories. The security level is an element of a hierarchically ordered set.
A very well-known example of such a set is the one including the levels TopSecret
(TS), Secret (S), Confidential (C), and Unclassified (U), where T S > S > C > U.
The set of categories is an unordered set (e.g. NATO, Nuclear, Army). Access classes
are partially ordered as follows. An access class c i dominates ≥ an access class c j
iff the security level of c i is greater than or equal to that of c j and the categories of
c i include those of c j .The security level of the access class reflects the sensitivity of
the information contained in the object. Categories are used to provide finer-grained
security classifications of subjects and objects. Access control is based on two principles, formulated by Bell and LaPadula, which are followed by all models enforcing
a mandatory security policy. The first states that a subject can read only those objects
whose access class is dominated by the access class of the subject; the second states
that a subject can write only those objects whose access class dominates the access
class of the subject. The application of MAC policies to relational DBMSs has been
extensively investigated over the past years. The introduction of such a model entails
the solution of several difficult issues. Because of this complexity, the adoption of
such a model in DBMSs is not as common as the next model.
Discretionary Access Control
These models are discretionary in the sense that they allow users to grant other users
authorization to access the data. Specifically, DAC policies regulate the access of
users on the basis of the user’s identity and authorizations that specify, for each user
(or group of users) and each object in the system, the access modes (e.g. read, write,
or execute) the user is allowed on the object. Each request of a user to access an
object is checked against the specified authorizations. If there exists an authorization
stating that the user can access the object in the specific mode, the access is granted,
otherwise it is denied [22]. Because of such flexibility, discretionary policies are
adopted in many applications. An important aspect of DAC is related to the authorization administration policy. Authorization administration refers to the function of
Maria Luisa Damiani and Elisa Bertino
its roots in academic and commercial research laboratories; the RBAC model, since
the seminal paper of [23], has gained increasingly consensus in the research community as well as in industry to finally become a standard widely adopted by
organizations [13].
Mandatory Access Control
Mandatory access control models control accesses on the basis of a predefined classification of subjects and objects in the system. Objects are the passive entities storing
information, such as relations in a DBMS. Subjects are active entities performing
data accesses. The classification is based on a number of access classes, also called
labels which are associated with every subject and object in the system. A subject is
granted authorization to access a given object if and only if some relationship, depending on the access mode, is satisfied between the classifications of the subject and
the object. An access class generally consists of two components: a security level and
a set of categories. The security level is an element of a hierarchically ordered set.
A very well-known example of such a set is the one including the levels TopSecret
(TS), Secret (S), Confidential (C), and Unclassified (U), where T S > S > C > U.
The set of categories is an unordered set (e.g. NATO, Nuclear, Army). Access classes
are partially ordered as follows. An access class c i dominates ≥ an access class c j
iff the security level of c i is greater than or equal to that of c j and the categories of
c i include those of c j .The security level of the access class reflects the sensitivity of
the information contained in the object. Categories are used to provide finer-grained
security classifications of subjects and objects. Access control is based on two principles, formulated by Bell and LaPadula, which are followed by all models enforcing
a mandatory security policy. The first states that a subject can read only those objects
whose access class is dominated by the access class of the subject; the second states
that a subject can write only those objects whose access class dominates the access
class of the subject. The application of MAC policies to relational DBMSs has been
extensively investigated over the past years. The introduction of such a model entails
the solution of several difficult issues. Because of this complexity, the adoption of
such a model in DBMSs is not as common as the next model.
Discretionary Access Control
These models are discretionary in the sense that they allow users to grant other users
authorization to access the data. Specifically, DAC policies regulate the access of
users on the basis of the user’s identity and authorizations that specify, for each user
(or group of users) and each object in the system, the access modes (e.g. read, write,
or execute) the user is allowed on the object. Each request of a user to access an
object is checked against the specified authorizations. If there exists an authorization
stating that the user can access the object in the specific mode, the access is granted,
otherwise it is denied [22]. Because of such flexibility, discretionary policies are
adopted in many applications. An important aspect of DAC is related to the authorization administration policy. Authorization administration refers to the function of
