Advanced transaction processing in multilevel secure file stores

被引:9
|
作者
Bertino, E [1 ]
Jajodia, S
Mancini, L
Ray, I
机构
[1] Univ Milan, Dipartimento Sci Informaz, Milan, Italy
[2] George Mason Univ, Dept Informat & Software Syst Engn, Fairfax, VA 22030 USA
[3] Univ Rome La Sapienza, Dipartimento Sci Informaz, Roma, Italy
基金
美国国家科学基金会;
关键词
data management system; file system management; transaction processing; concurrency control; two-phase locking; exception handling; security kernel; mandatory access control; covert channels;
D O I
10.1109/69.667095
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The concurrency control requirements for transaction processing in a multilevel secure file system are different from those in conventional transaction processing systems. In particular, there is the need to coordinate transactions at different security levels avoiding both potential timing covert channels and the starvation of transactions at higher security levels. Suppose a transaction at a lower security level attempts to write a data item that is being read by a transaction at a higher security level. On the one hand, a timing covert channel arises if the transaction at the lower security level is either delayed or aborted by the scheduler. On the other hand, the transaction at the high security level may be subjected to an indefinite delay if it is forced to abort repeatedly. This paper extends the classical two-phase locking mechanism to multilevel secure file systems. The scheme presented here prevents potential timing covert channels and avoids the abort of higher level transactions nonetheless guaranteeing serializability. The programmer is provided with a powerful set of linguistic constructs that supports exception handling, partial rollback, and forward recovery. The proper use of these constructs can prevent the indefinite delay in completion of a higher level transaction, and allows the programmer to trade off starvation with transaction isolation.
引用
收藏
页码:120 / 135
页数:16
相关论文
共 50 条
  • [1] An extended transaction model approach for multilevel secure transaction processing
    Atluri, V
    Mukkamala, R
    [J]. DATABASE AND APPLICATION SECURITY XV, 2002, 87 : 255 - 268
  • [2] Multilevel secure transaction processing: Status and prospects
    Atluri, V
    Jajodia, S
    Keefe, TF
    McCollum, C
    Mukkamala, R
    [J]. DATABASE SECURITY VOLUME X - STATUS AND PROSPECTS, 1997, : 79 - 98
  • [3] ON TRANSACTION PROCESSING FOR MULTILEVEL SECURE REPLICATED DATABASES
    KANG, IE
    KEEFE, TF
    [J]. LECTURE NOTES IN COMPUTER SCIENCE, 1992, 648 : 329 - 347
  • [4] A multi-threading architecture for multilevel secure transaction processing
    Isa, HR
    Shockley, WR
    Irvine, CE
    [J]. PROCEEDINGS OF THE 1999 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 1999, : 166 - 180
  • [5] Transaction processing in multilevel secure databases with kernelized architecture: Challenges and solutions
    Atluri, V
    Jajodia, S
    Bertino, E
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1997, 9 (05) : 697 - 708
  • [6] A transaction processing model for performance analysis in multilevel-secure database systems
    Kang, S
    Kim, SS
    Lee, G
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 2, 2006, 3981 : 1060 - 1065
  • [7] Advanced transaction scheduling protocol for multilevel secure database in wireless mobile network environment
    Kim, HW
    Park, DS
    Rhee, HK
    Kim, UM
    [J]. JOINT 4TH IEEE INTERNATIONAL CONFERENCE ON ATM (ICATM'01) AND HIGH SPEED INTELLIGENT INTERNET SYMPOSIUM, 2001, : 240 - 244
  • [8] Supporting secure canonical upgrade policies in multilevel secure object stores
    Foley, SN
    [J]. 13TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 1997, : 69 - 80
  • [9] A PRACTICAL TRANSACTION MODEL AND UNTRUSTED TRANSACTION MANAGER FOR A MULTILEVEL-SECURE DATABASE SYSTEM
    KANG, MOH
    COSTICH, O
    FROSCHER, JN
    [J]. IFIP TRANSACTIONS A-COMPUTER SCIENCE AND TECHNOLOGY, 1993, 21 : 285 - 300
  • [10] A multiversion transaction scheduler for centralized multilevel secure database systems
    Keefe, TF
    Tsai, WT
    [J]. IEEE HIGH-ASSURANCE SYSTEMS ENGINEERING WORKSHOP, PROCEEDINGS, 1997, : 206 - 213