HDS ViewStation System Administrator's Guide

A Hypertext Document


ViewStation with CMW Security

This page describes an optional CMW Security system for the ViewStation.

CMW Security
The HDS ViewStation supports Compartmentalized Workstation (CMW) security, in which applications and processes are controlled by a "Trusted Client", typically a window manager. This trusted client maintains labels containing permission levels for all windows, X atoms, and pieces of data for all clients and servers. These labels are examined with each transaction and a detailed audit trail is maintained. This CMW security meets U.S. Government B1 level security, using the NSA rating procedure.

CMW Security Features
This section summarizes the compartmentalized workstation secure window interface for the HDS ViewStation terminal. This includes modifications to the server software based on X11R4. These comprise the TCB (Trusted Computing Base).

There are two main features of CMW security:
1. Trusted X server, including all server operations, with the Motif window manager.

2. Trusted Motif window manager, including label display and trusted paths.

Four specific security categories are addressed:

1) Associating labels with all window system objects. This includes a set of client identifications and labels, as well as labels for Atom Names, Properties, Colormaps, Pixmaps, and Drawables. For any Drawable (a window or a pixmap), the trusted X server uses three labels:
Sensitivity label (normally set equal to the parenting client sensitivity, but modifiable)
Information label (dynamically modified with window operations)
Input information label (which determines the acceptable input events sent to the window)

2) Access control and operating restrictions for trusted clients. There are two specific controls applied;
Certain window objects are accessible only to their single creating client
Shared objects are controlled by explicit, mandatory control checking.

3) Protocol extensions and modifications for the trusted window manager. The window manager operations are modified in five ways:
Cut/paste operations are governed by authentication clients; data transferred is label verified.
Authentication procedures are given to the trusted window manager, including starting new sessions.
Support for window-based trusted paths, including reserved screen areas.
Support for label modification (clear or reset operations) processes.
Support for inactive session or timeout processes from a configurable logoff event.

4) Auditing events and security concerns. The trusted X server and trusted window manager create and maintain audit records for these events:
Creation and destruction of window system objects
Explicit changes to window labels
Implicit changes to information labels resulting from floats
Access denials resulting from access control checking
Access denials resulting from lack of privilege
Client use of privilege
Server reinitializations

Return to Section Heading Page


Return to the Home Page

If you need more information than is available here, you can reach HDS via email at info@hds.com, or call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside the US. For questions or problems regarding the HDS WWW page, contact webmaster@hds.com.
© 1996 by HDS Network Systems Inc.