Wikipedia

Lattice-based access control

In computer security, lattice-based access control (LBAC) is a complex access control model based on the interaction between any combination of objects (such as resources, computers, and applications) and subjects (such as individuals, groups or organizations).

In this type of label-based mandatory access control model, a lattice is used to define the levels of security that an object may have and that a subject may have access to. The subject is only allowed to access an object if the security level of the subject is greater than or equal to that of the object.

Mathematically, the security level access may also be expressed in terms of the lattice (a partial order set) where each object and subject have a greatest lower bound (meet) and least upper bound (join) of access rights. For example, if two subjects A and B need access to an object, the security level is defined as the meet of the levels of A and B. In another example, if two objects X and Y are combined, they form another object Z, which is assigned the security level formed by the join of the levels of X and Y.

LBAC is also known as a label-based access control (or rule-based access control) restriction as opposed to role-based access control (RBAC).

Lattice based access control models were first formally defined by Denning (1976); see also Sandhu (1993).

See also

References

  • Denning, Dorothy E. (1976). "A lattice model of secure information flow" (PDF). Communications of the ACM. 19 (5): 236–243. doi:10.1145/360051.360056.
  • Sandhu, Ravi S. (1993). "Lattice-based access control models" (PDF). IEEE Computer. 26 (11): 9–19. doi:10.1109/2.241422.


This article is copied from an article on Wikipedia® - the free encyclopedia created and edited by its online user community. The text was not checked or edited by anyone on our staff. Although the vast majority of Wikipedia® encyclopedia articles provide accurate and timely information, please do not assume the accuracy of any particular article. This article is distributed under the terms of GNU Free Documentation License.

Copyright © 2003-2025 Farlex, Inc Disclaimer
All content on this website, including dictionary, thesaurus, literature, geography, and other reference data is for informational purposes only. This information should not be considered complete, up to date, and is not intended to be used in place of a visit, consultation, or advice of a legal, medical, or any other professional.