Skip to content

Bell–LaPadula Model

A formal multilevel-security state model that preserves classified-information confidentiality through subject/object labels, permitted access modes, and secure-state transitions.

Version
v1 · 2026-09-28 · History
Domain-specific #
8159
Domain group
Applied Sciences & Engineering
Origin domain
Computer Science & Software Engineering
Subdomains
Computer Security, Multilevel Access Control → Computer Science & Software Engineering
Aliases
BLP Model, Bell-LaPadula Model

Core Idea

Bell–LaPadula expresses multilevel confidentiality as a state-machine invariant. Subjects and objects carry security levels, including compartments; operations are admitted only if the mandatory simple-security and star properties and applicable discretionary permissions hold.

Its memorable boundary is no read up and no write down for ordinary subjects. A secure starting state plus secure transitions yields a formal policy claim, not a guarantee against every covert channel, implementation flaw, or integrity violation.

How would you explain it like I'm…

No Peeking Up, No Leaking Down

Imagine papers marked 'secret' and 'top secret,' and people who are each allowed up to a certain level. The Bell-LaPadula rules say you can't read papers above your level, and you can't write into papers at a lower level, so secrets can't sneak down to people who shouldn't see them.

No Read Up, No Write Down

The Bell-LaPadula Model is a set of rules for keeping secret information in computers from leaking. Every user or program and every file gets a security level, like 'confidential' or 'top secret,' plus special categories. The two main rules are 'no read up' (you can't read something above your level) and 'no write down' (you can't copy information into something at a lower level). If the system starts out safe and every action follows the rules, it stays safe by these rules. It's about keeping secrets, not about stopping every possible sneaky trick or making sure information is correct.

Multilevel Confidentiality Model

The Bell-LaPadula Model is a formal model of multilevel confidentiality written as a state machine. Subjects (users and processes) and objects (files and data) have security levels that include both a rank and compartments. An operation is allowed only if two mandatory rules hold, the simple-security property ('no read up') and the star property ('no write down' for ordinary subjects), along with any discretionary permissions. If the system begins in a secure state and every transition keeps those properties, it remains secure by the model's definition. That is a formal policy guarantee, not a promise against covert channels, bugs in the implementation, or corruption of data (integrity).

 

The Bell–LaPadula Model formalizes multilevel confidentiality as an invariant of a state machine. Subjects and objects carry security levels composed of a classification and a set of compartments, ordered by dominance. A requested access is granted only if it satisfies the mandatory simple-security property, under which a subject may read an object only if the subject's level dominates the object's, and the star property, under which a subject may write only to objects whose level dominates its own, together with any applicable discretionary access permissions. For ordinary subjects this is summarized as no read up and no write down. The model's basic security result is inductive: a secure initial state together with transitions that each preserve the properties yields only secure reachable states. This is a formal claim about the policy, not a guarantee against covert channels, implementation flaws, or violations of integrity, which the model does not address.

Scope of Application

Bell–LaPadula specifies confidentiality in systems with ordered classification levels and modeled access transitions.

  • Multilevel security. Governs reads and writes among subjects and objects carrying clearance and classification labels.
  • Formal policy analysis. Checks whether permitted operations preserve a secure state from a secure starting state.
  • Classified-information systems. Supplies the historical setting for ordered levels, compartments, and trusted exceptions.
  • Model comparison. Contrasts confidentiality-oriented flow restrictions with Biba-style integrity and discretionary control alone.

Clarity

Specify subject clearance, object classification, compartments, and whether the proposed access reads or writes. Ordinary Bell–LaPadula checks no read up and no write down together with discretionary permission and secure transitions. Its result is a conditional confidentiality-policy verdict, not a proof of integrity, freedom from covert channels, or secure implementation. Even a mandatory-rule pass is insufficient if the discretionary permission or secure-transition condition fails.

Manages Complexity

A labeled system has many actors, objects, modes, permissions, and changing states. Bell–LaPadula compresses their confidentiality relation into mandatory read/write direction rules, discretionary checks, and an invariant over permitted transitions. The compression is useful precisely because the protected objective is narrow; unmodeled channels, implementation faults, and data integrity remain separate questions.

Abstract Reasoning

Place subjects and objects in the label order, identify the access mode and any trusted exception, and apply the simple-security and star properties. Check discretionary permission and whether the transition preserves a secure state. Report only the model's confidentiality conclusion, leaving unmodeled channels and deployment behavior outside it. This yields a verdict about specified accesses rather than all possible information leaks.

Knowledge Transfer

Bell–LaPadula is a specific kind of access-control model: subject, object, action, and policy decisions are inherited from that broader relation, while ordered labels and secure-state confidentiality rules specify this child. Its label-order test can inform other multilevel analyses only after their modes and exceptions are defined. Biba instead prioritizes integrity, and a deployed product is not proved secure merely because it uses labels or cites Bell–LaPadula.

Relationships to Other Abstractions

Local relationship map for Bell–LaPadula ModelParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Bell–LaPadula ModelDOMAINPrime abstraction: Access Control — is a kind ofAccess ControlPRIME

Current abstraction Bell–LaPadula Model Domain-specific

Parents (1) — more general patterns this builds on

  • Bell–LaPadula Model is a kind of Access Control Prime

    A multilevel access-control model that constrains subject–object reads and writes to preserve confidentiality.

Hierarchy paths (3) — routes to 3 parentless roots

Neighborhood in Abstraction Space

Bell–LaPadula Model sits in a crowded region of the domain-specific corpus (30th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.

Family — Formal Systems & Discrete Structures (18 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08