This page describes an optional CMW Security system for the
ViewStation.
CMW Security
The HDS ViewStation supports Compartmentalized Workstation (CMW)
security, in which applications and processes are controlled by a
"Trusted Client", typically a window manager. This trusted client
maintains labels containing permission levels for all windows, X atoms,
and pieces of data for all clients and servers. These labels are
examined with each transaction and a detailed audit trail is maintained.
This CMW security meets U.S. Government B1 level security, using the
NSA rating procedure.
CMW Security Features
This section summarizes the compartmentalized workstation secure
window interface for the HDS ViewStation terminal. This includes
modifications to the server software based on X11R4. These comprise the
TCB (Trusted Computing Base).
There are two main features of
CMW security:
1. Trusted X server, including all server operations, with the
Motif window manager.
2. Trusted Motif window manager, including label display and
trusted paths.
Four specific security categories are addressed:
1) Associating labels with all window system objects. This
includes a set of client identifications and labels, as well as labels
for Atom Names, Properties, Colormaps, Pixmaps, and Drawables. For any
Drawable (a window or a pixmap), the trusted X server uses three
labels:
Sensitivity label (normally set equal to the parenting client
sensitivity, but modifiable)
Information label (dynamically modified with window operations)
Input information label (which determines the acceptable input
events sent to the window)
2) Access control and operating restrictions for trusted
clients. There are two specific controls applied;
Certain window objects are accessible only to their single creating
client
Shared objects are controlled by explicit, mandatory control
checking.
3) Protocol extensions and modifications for the trusted
window manager. The window manager operations are modified in five
ways:
Cut/paste operations are governed by authentication clients; data
transferred is label verified.
Authentication procedures are given to the trusted window manager,
including starting new sessions.
Support for window-based trusted paths, including reserved screen
areas.
Support for label modification (clear or reset operations)
processes.
Support for inactive session or timeout processes from a
configurable logoff event.
4) Auditing events and security concerns. The trusted X server
and trusted window manager create and maintain audit records for these
events:
Creation and destruction of window system objects
Explicit changes to window labels
Implicit changes to information labels resulting from floats
Access denials resulting from access control checking
Access denials resulting from lack of privilege
Client use of privilege
Server reinitializations
Return to Section Heading Page
Return to the Home Page
If you need more information than is available here, you can reach
HDS via email at info@hds.com, or
call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside
the US. For questions or problems regarding the HDS WWW page, contact
webmaster@hds.com.
© 1996 by HDS Network Systems
Inc.