• DocumentCode
    1534907
  • Title

    Compartmented mode workstation: prototype highlights

  • Author

    Berger, Jeffrey L. ; Picciotto, Jeffrey ; Woodward, John P L ; Cummings, Paul T.

  • Author_Institution
    MITRE Corp., Bedford, MA, USA
  • Volume
    16
  • Issue
    6
  • fYear
    1990
  • fDate
    6/1/1990 12:00:00 AM
  • Firstpage
    608
  • Lastpage
    618
  • Abstract
    The primary goal of the MITRE compartmented mode workstation (CMW) project was to articulate the security requirements that workstations must meet to process highly classified intelligence data. As a basis for the validity of the requirements developed, a prototype was implemented which demonstrated that workstations could meet the requirements in an operationally useful manner while still remaining binary compatible with off-the-shelf software. The security requirements not only addressed traditional security concerns but also introduced concepts in areas such as labeling and the use of a trusted window management system. The CMW labeling paradigm is based on associating two types of security labels with objects: sensitivity levels and information labels. Sensitivity levels describe the levels at which objects must be protected. Information labels are used to prevent data overclassification and also provide a mechanism for associating with data those markings that are required for accurate data labeling, but which play no role in access control decisions. The use of a trusted window manager allows users to easily operate at multiple sensitivity levels and provides a convenient mechanism for communicating security information to users in a relatively unobtrusive manner
  • Keywords
    security of data; software engineering; workstations; MITRE compartmented mode workstation; accurate data labeling; binary compatible; data overclassification prevention; highly classified intelligence data; information labels; markings; multiple sensitivity levels; objects; security labels; security requirements; sensitivity levels; trusted window management system; Access control; Computer security; Data security; Environmental economics; Information security; Labeling; Power generation economics; Protection; Prototypes; Workstations;
  • fLanguage
    English
  • Journal_Title
    Software Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0098-5589
  • Type

    jour

  • DOI
    10.1109/32.55089
  • Filename
    55089