Abstract
A database system must have knowledge of the semantics (the properties) of the data it manages to accomplish its tasks. For a multilevel secure database system to provide effective multilevel support to users, it must have knowledge of the security-relevant data semantics. The use of an extended data model that represents both integrity and secrecy aspects of data is presented. The technique can be used as a database design tool and, more importantly, as a vehicle by which domain experts, database designers, and security officers can precisely define the security requirements for an application domain. A second contribution is a comprehensive taxonomy of security-relevant data semantics that must be captured and understood to implement a multilevel secure automated information system.

This publication has 20 references indexed in Scilit: