The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

The Seaview Formal Security Policy Model


Teresa F. Lunt, Dorothy E. denning, Roger R. schell, Mark Heckman, William R. Shockley

Entry type



This report describes a formal security policy model for a secure relational database system. This model is intended to meet the formal model requirement specified in the DoD Trusted Computer System Evaluation criteria. The model is formulated in two layers, one corresponding to a reference monitor that enforces mandatory security, and the second defining multilevel relations and formalizing policies for labeling new and derived data, data consistency, discretionary security, and transaction consistency. The development of a formal security policy model is the second task of the SeaView project to design a multilevel secure database system meeting the Criteria for Class A1.


1989 – February – 1

Key alpha



SRI International, Gemini Computers

Publication Date



1. Background 2. Security Model Overview 3. Mandatory Security Policy Model 4. TCB Multilevel Relations 5. TCB Application-Specific Constraints on Values and Classes 6. TCB Discretionary Security 7. TCB Transactions 8. TCB Model Interface




A hard-copy of this is in Haas


formal security policy model

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.