NASA Logo

NTRS

NTRS - NASA Technical Reports Server

Back to Results
Theft of information in the take-grant protection modelQuestions of information flow are in many ways more important than questions of access control, because the goal of many security policies is to thwart the unauthorized release of information, not merely the illicit obtaining of access rights to that information. The Take-Grant Protection Model is a theoretical tool for examining such issues because conditions necessary and sufficient for information to flow between two objects, and for rights to objects to be obtained or stolen, are known. These results are extended by examining the question of information flow from an object the owner of which is unwilling to release that information. Necessary and sufficient conditions for such theft of information to occur are derived, and bounds on the number of subjects that must take action for the theft to occur are presented. To emphasize the usefulness of these results, the security policies of complete isolation, transfer of rights with the cooperation of an owner, and transfer of information (but not rights) with the cooperation of the owner are presented; the last is used to model a simple reference monitor guarding a resource.
Document ID
19900016386
Acquisition Source
Legacy CDMS
Document Type
Contractor Report (CR)
Authors
Bishop, Matt
(Dartmouth Coll. Hanover, NH, United States)
Date Acquired
September 6, 2013
Publication Date
January 1, 1989
Subject Category
Documentation And Information Science
Report/Patent Number
PCS-TR88-137-REV
NAS 1.26:186638
NASA-CR-186638
Report Number: PCS-TR88-137-REV
Report Number: NAS 1.26:186638
Report Number: NASA-CR-186638
Accession Number
90N25702
Funding Number(s)
CONTRACT_GRANT: NAG2-480
Distribution Limits
Public
Copyright
Work of the US Gov. Public Use Permitted.
No Preview Available