Approaches to formal modelling access control in PostgreSQL within framework of the MROSL DP-model
Prikladnaya Diskretnaya Matematika. Supplement, no. 11 (2018), pp. 95-99.

Voir la notice de l'article provenant de la source Math-Net.Ru

PostgreSQL is widely used in the trusted operating systems. Therefore, the scientific approaches to an implementation of the access control security in PostgreSQL have to be developed. Firstly, it is required to analyze a role-based access control (RBAC) that was originally implemented in PostgreSQL. Secondly, we have to study the mandatory access control (MAC) and the mandatory integrity control (MIC) in practice of trusted operating systems development. Now, the mandatory entity-role DP-model (MROSL DP-model) is becoming the scientific basis of access control policy in OS of Linux family, for example in OS Astra Linux Special Edition. This model includes RBAC, MAC and MIC. The model has also a hierarchical structure, which allows to supplement the model with new elements without its full processing. In addition, the model was affirmed as correct by the tools of deductive verification. This article presents the approaches that are proposed for constructing new levels within the framework of the hierarchical representation of the MROSL DP-model related to access control in PostgreSQL. At the same time, the first stage of modelling focuses on RBAC due to the significant differences between access control principals in OS Astra Linux Special Edition and PostgreSQL.
Keywords: computer security, formal model, access control, PostgreSQL.
@article{PDMA_2018_11_a28,
     author = {P. N. Devyanin},
     title = {Approaches to formal modelling access control in {PostgreSQL} within framework of the {MROSL} {DP-model}},
     journal = {Prikladnaya Diskretnaya Matematika. Supplement},
     pages = {95--99},
     publisher = {mathdoc},
     number = {11},
     year = {2018},
     language = {ru},
     url = {http://geodesic.mathdoc.fr/item/PDMA_2018_11_a28/}
}
TY  - JOUR
AU  - P. N. Devyanin
TI  - Approaches to formal modelling access control in PostgreSQL within framework of the MROSL DP-model
JO  - Prikladnaya Diskretnaya Matematika. Supplement
PY  - 2018
SP  - 95
EP  - 99
IS  - 11
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/PDMA_2018_11_a28/
LA  - ru
ID  - PDMA_2018_11_a28
ER  - 
%0 Journal Article
%A P. N. Devyanin
%T Approaches to formal modelling access control in PostgreSQL within framework of the MROSL DP-model
%J Prikladnaya Diskretnaya Matematika. Supplement
%D 2018
%P 95-99
%N 11
%I mathdoc
%U http://geodesic.mathdoc.fr/item/PDMA_2018_11_a28/
%G ru
%F PDMA_2018_11_a28
P. N. Devyanin. Approaches to formal modelling access control in PostgreSQL within framework of the MROSL DP-model. Prikladnaya Diskretnaya Matematika. Supplement, no. 11 (2018), pp. 95-99. http://geodesic.mathdoc.fr/item/PDMA_2018_11_a28/

[1] Informatsionnoe soobschenie ob utverzhdenii Trebovanii bezopasnosti informatsii k operatsionnym sistemam ot 18 oktyabrya 2016 g., No 240/24/4893/ FSTEK Rossii, http://fstec.ru/component/attachments/download/1051

[2] Informatsionnaya tekhnologiya. Metody i sredstva obespecheniya bezopasnosti. Kriterii otsenki bezopasnosti informatsionnykh tekhnologii, GOST R ISO/MEK 15408-2013

[3] Operatsionnye sistemy Astra Linux, http://www.astralinux.com/

[4] Astra Linux, https://ru.wikipedia.org/wiki/Astra_Linux

[5] Burenin P. V., Devyanin P. N., Lebedenko E. V. i dr., Bezopasnost operatsionnoi sistemy spetsialnogo naznacheniya Astra Linux Special Edition, Ucheb. posobie dlya vuzov, 2-e izd., stereotip., ed. P. N. Devyanin, Goryachaya liniya – Telekom, M., 2016, 312 pp.

[6] Devyanin P. N., “Realizatsiya nevyrozhdennoi reshëtki urovnei tselostnosti v ramkakh ierarkhicheskogo predstavleniya MROSL DP-modeli”, Prikladnaya diskretnaya matematika. Prilozhenie, 2017, no. 10, 111–114

[7] Devyanin P. N., Modeli bezopasnosti kompyuternykh sistem. Upravlenie dostupom i informatsionnymi potokami, Ucheb. posobie dlya vuzov, 2-e izd., ispr. i dop., Goryachaya liniya – Telekom, M., 2013, 338 pp.

[8] Devyanin P. N., “Uroven zapreschayuschikh rolei ierarkhicheskogo predstavleniya MROSL DP-modeli”, Prikladnaya diskretnaya matematika, 2018, no. 39, 58–71

[9] Devyanin P. N., Kulyamin V. V., Petrenko A. K., i dr., “O predstavlenii MROSL DP-modeli v formalizovannoi notatsii Event-B”, Problemy informatsionnoi bezopasnosti. Kompyuternye sistemy, 2014, no. 3, 7–15

[10] Astra Linux sertifitsirovana po trebovaniyam FSTEK Rossii k operatsionnym sistemam, http://astralinux.com/home/novosti/437-rbt-fstec.html

[11] Shumilin A. V., “Osnovnye elementy mandatnoi suschnostno-rolevoi DP-modeli upravleniya dostupom i informatsionnymi potokami v SUBD PostgreSQL OS spetsialnogo naznacheniya Astra Linux Special Edition”, Prikladnaya diskretnaya matematika, 2013, no. 3(21), 52–67

[12] Smolyaninov V. Yu., “Analiz uslovii predostavleniya i polucheniya prav dostupa v modeli upravleniya dostupom MS SQL Server”, Prikladnaya diskretnaya matematika, 2014, no. 2(24), 48–78