TY - JOUR
T1 - A design of MAC model based on the separation of duties and data coloring
T2 - DSDC-MAC
AU - Lee, Soon Book
AU - Kim, Yoo Hwan
AU - Kim, Jin Woo
AU - Song, Chee Yang
N1 - Publisher Copyright:
© 2020 Soon-Book Lee, Yoo-Hwan Kim, Jin-Woo Kim and Chee-Yang Song.
PY - 2020
Y1 - 2020
N2 - Among the access control methods for database security, there is Mandatory Access Control (MAC) model in which the security level is set to both the subject and the object to enhance the security control. Legacy MAC models have focused only on one thing, either confidentiality or integrity. Thus, it can cause collisions between security policies in supporting confidentiality and integrity simultaneously. In addition, they do not provide a granular security class policy of subjects and objects in terms of subjects' roles or tasks. In this paper, we present the security policy of Bell_LaPadula Model (BLP) model and Biba model as one complemented policy. In addition, Duties Separation and Data Coloring (DSDC)-MAC model applying new data coloring security method is proposed to enable granular access control from the viewpoint of Segregation of Duty (SoD). The case study demonstrated that the proposed modeling work maintains the practicality through the design of Human Resources management System. The proposed model in this study is suitable for organizations like military forces or intelligence agencies where confidential information should be carefully handled. Furthermore, this model is expected to protect systems against malicious insiders and improve the confidentiality and integrity of data.
AB - Among the access control methods for database security, there is Mandatory Access Control (MAC) model in which the security level is set to both the subject and the object to enhance the security control. Legacy MAC models have focused only on one thing, either confidentiality or integrity. Thus, it can cause collisions between security policies in supporting confidentiality and integrity simultaneously. In addition, they do not provide a granular security class policy of subjects and objects in terms of subjects' roles or tasks. In this paper, we present the security policy of Bell_LaPadula Model (BLP) model and Biba model as one complemented policy. In addition, Duties Separation and Data Coloring (DSDC)-MAC model applying new data coloring security method is proposed to enable granular access control from the viewpoint of Segregation of Duty (SoD). The case study demonstrated that the proposed modeling work maintains the practicality through the design of Human Resources management System. The proposed model in this study is suitable for organizations like military forces or intelligence agencies where confidential information should be carefully handled. Furthermore, this model is expected to protect systems against malicious insiders and improve the confidentiality and integrity of data.
KW - Complemented BLP and Biba model
KW - Data coloring access control
KW - Mandatory access control (MAC)
KW - Security key authorization
KW - SoD-driven access control
UR - http://www.scopus.com/inward/record.url?scp=85082043658&partnerID=8YFLogxK
U2 - 10.3844/jcssp.2020.72.91
DO - 10.3844/jcssp.2020.72.91
M3 - Article
AN - SCOPUS:85082043658
SN - 1549-3636
VL - 16
SP - 72
EP - 91
JO - Journal of Computer Science
JF - Journal of Computer Science
IS - 1
ER -