Skip to content

Biba Model

A mandatory access-control integrity model that orders subjects and objects by integrity level and restricts information flow to prevent lower-integrity data from contaminating higher-integrity state.

Version
v1 · 2026-09-08 · History
Domain-specific #
3453
Origin domain
computer security models
Subdomain
computer security models

Core Idea

Biba's strict integrity policy is commonly summarized as no read down and no write up, the integrity-oriented dual of Bell-LaPadula confidentiality, with variants for invocation and dynamic policy. Labels order trust; reference-monitor rules test every read, write, and invocation against subject and object levels so permitted state transitions preserve the declared integrity invariant. The abstraction is therefore identified by a declared carrier, a transformation or constraint over that carrier, and an invariant that tells an analyst whether the named structure is genuinely present.

Scope of Application

Biba Model belongs to computer security models and is useful where the analyst can specify the typed computer security models carrier, defining objects and relations, parameters, conventions, evidence, boundary cases, and comparison targets, then evaluate the subjects and objects, integrity lattice and dominance relation, read, write and invocation semantics, transition rules, trusted subjects, declassification or endorsement, covert channels, and exact Biba variant are explicit. The scope is broad within that domain but bounded by the need for the subjects and objects, integrity lattice and dominance relation, read, write and invocation semantics, transition rules, trusted subjects, declassification or endorsement, covert channels, and exact Biba variant are explicit.

Clarity

The abstraction clarifies a crowded vocabulary by making the subjects and objects, integrity lattice and dominance relation, read, write and invocation semantics, transition rules, trusted subjects, declassification or endorsement, covert channels, and exact Biba variant are explicit the center of the account. A claim should name the carrier, the governing operation or relation, the applicable assumptions, and the recognition test.

Manages Complexity

Without the abstraction, an analyst must reason directly over many local details: the carrier roles, admissibility assumptions, competing conventions, derived invariants, boundary cases, and proof or validation obligations specific to Biba Model. Biba Model compresses them into the roles in the structural signature. That compression permits comparison across instances without erasing the variables that determine validity. It also exposes which details may be varied safely and which are constitutive.

Abstract Reasoning

  1. Identify the carrier. State what the elements, states, objects, or observations are: the typed computer security models carrier, defining objects and relations, parameters, conventions, evidence, boundary cases, and comparison targets. Reject examples whose alleged carrier belongs to a different problem. 2. Lock the constitutive rule. Express the subjects and objects, integrity lattice and dominance relation, read, write and invocation semantics, transition rules, trusted subjects, declassification or endorsement, covert channels, and exact Biba variant are explicit independently of one notation or implementation.

Knowledge Transfer

Knowledge transfers strongly among subfields of computer security models because they reuse the typed computer security models carrier, defining objects and relations, parameters, conventions, evidence, boundary cases, and comparison targets, Labels order trust; reference-monitor rules test every read, write, and invocation against subject and object levels so permitted state transitions preserve the declared integrity invariant., and type the carrier, state every parameter and convention in the definition, test that the subjects and objects, integrity lattice and dominance relation, read, write and invocation semantics, transition rules, trusted subjects, declassification or endorsement, covert channels, and exact Biba variant are explicit, compare the nearest accepted identity, and report counterexamples, uncertainty, and limiting cases.

Relationships to Other Abstractions

Local relationship map for Biba ModelParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Biba ModelDOMAINPrime abstraction: Data Integrity — is a kind ofData IntegrityPRIME

Current abstraction Biba Model Domain-specific

Parents (1) — more general patterns this builds on

  • Biba Model is a kind of Data Integrity Prime

    The proposed strict upward parent is prime:data_integrity.

Hierarchy paths (2) — routes to 2 parentless roots

Neighborhood in Abstraction Space

Biba Model sits in a moderately populated region (47th percentile for distinctiveness): it has near-neighbors but no dense thicket of look-alikes.

Family — Algorithms, Proofs & Computational Decisions (25 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-09-08