Skip to content

Harrison–Ruzzo–Ullman Security Model

An access-control transition model of subjects, objects, rights-valued matrix cells, and guarded commands whose general new-right leakage safety problem is undecidable.

Version
v1 · 2026-09-28 · History
Domain-specific #
9915
Domain group
Applied Sciences & Engineering
Origin domain
Computer Science & Software Engineering
Subdomains
Computer Security, Access Control → Computer Science & Software Engineering
Aliases
HRU Security Model, HRU Model, Harrison Ruzzo Ullman Model

Core Idea

HRU gives access control an operational semantics. A configuration consists of subjects, objects, and an access matrix; guarded commands atomically add or remove rights and create or delete subjects and objects.

Safety is a reachability property, not a snapshot check: can some legal command sequence cause a selected right to appear in a cell where it was initially absent? Harrison, Ruzzo, and Ullman showed that this question is undecidable for the general model, while restricted command forms can be decidable.

Structural Signature

Sig role-phrases:

  • Subjects — Occupy matrix rows and may execute commands. It is active entities. Counterfactual: Objects alone cannot request state changes.
  • Objects — Occupy columns and receive controlled operations. It is resource entities. Counterfactual: Unmodeled resources have no rights state.
  • Access-right matrix — Maps each subject–object pair to a set of rights. It is state representation. Counterfactual: A role list without cell structure is another model.
  • Guarded commands — Specify enabled transformations using rights preconditions. It is transition rules. Counterfactual: Arbitrary state change defeats the protection system definition.
  • Primitive updates — Enter/delete rights and create/delete subjects or objects. It is state mutation. Counterfactual: Policy prose without primitives cannot support reachability analysis.
  • Safety query — Asks whether a specified right can leak to a new cell along any execution. It is verification target. Counterfactual: Checking only the initial matrix misses reachability.

What It Is Not

  • It is not merely a static permission table.
  • Safety here is a specific right-leakage predicate.
  • Undecidability does not make every restricted instance unanalyzable.
  • The model does not by itself prove implementation security.
  • Closest near-miss. The Graham–Denning model also uses access matrices and transformations; HRU emphasizes the formal command system and the general undecidability boundary for safety.

Scope of Application

  • Access-control theory. Formalizes administrative rights changes.
  • Operating-system security. Models subjects, objects, and permissions.
  • Formal verification. Locates decidability boundaries.
  • Security-policy design. Shows costs of expressive delegation.

Clarity

State initial subjects, objects, rights, full matrix, command parameters, guards, primitive effects, atomicity, entity-creation bounds, queried right and cell condition, and any restriction used for decidability.

Manages Complexity

HRU reduces protection administration to reachability over matrix-transforming commands and exposes how modest operational expressiveness yields an unbounded verification problem.

Abstract Reasoning

  1. Encode the initial access configuration.
  2. Translate each administrative action into guards and primitives.
  3. Define the exact leakage predicate.
  4. Determine whether the model lies in a decidable restriction.
  5. Use sound analysis without claiming a general algorithm where none exists.

Knowledge Transfer

HRU conclusions transfer only when another system's principals, resources, rights, commands, atomicity, creation power, and safety predicate are faithfully encoded; RBAC or capability semantics require explicit mapping.

Examples

Canonical

From an initial matrix, a guarded command checks an owner right and atomically enters read in another subject's file cell; safety asks whether any sequence can place a chosen right in a cell that initially lacked it.

Mapped back: subjects → grantor and grantee; object → file; matrix → rights sets; guard → owner present; mutation → enter read; query → new-right reachability.

Applied / In Practice

Listing who currently has read permission is a static audit, not an HRU safety analysis unless commands and future reachability are modeled.

Mapped back: matrix snapshot → present; commands → absent; reachability → absent.

Structural Tensions

T1 — Expressive Administration versus Decidable Verification. Rich commands model realistic delegation but make general safety undecidable.

Diagnostic: What syntactic restriction recovers a decision procedure?

T2 — Finite Current State versus Unbounded Evolution. Each configuration is finite while creation and arbitrary sequences make reachability unbounded.

Diagnostic: Which bounds on entities or operations are maintained?

Structural–Framed Character

HRU is structural as access-matrix reachability and security-framed by rights, commands, and leakage.

Structural Core vs. Domain Accent

The core is state carrier, guarded transitions, and reachability query. Security theory supplies principals, access rights, safety interpretation, and undecidability result.

This entry presupposes Access Control.

  • Approved root. No reviewed parent entails this protection-system transition model.

  • Related — access matrix, Graham–Denning model, safety property, reachability, and undecidability. They provide representation, predecessor, query class, method, and limit.

Relationships to Other Abstractions

Local relationship map for Harrison–Ruzzo–Ullman Security ModelParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Harrison–Ruzzo–UllmanSecurity ModelDOMAINPrime abstraction: Access Control — presupposesAccess ControlPRIME

Current abstraction Harrison–Ruzzo–Ullman Security Model Domain-specific

Parents (1) — more general patterns this builds on

  • Harrison–Ruzzo–Ullman Security Model presupposes Access Control Prime

    Harrison–Ruzzo–Ullman Security Model presupposes Access Control because the model represents subjects, objects, rights, and guarded access-control transitions.

Hierarchy paths (3) — routes to 3 parentless roots

Neighborhood in Abstraction Space

Harrison–Ruzzo–Ullman Security Model sits in a crowded region of the domain-specific corpus (30th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.

Family — Formal Systems & Discrete Structures (18 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08

Not to Be Confused With

  • Static access matrix. Tell: Has no transition commands or reachability.
  • Role-based access control. Tell: Organizes permissions through roles rather than HRU cells directly.
  • Bell–LaPadula. Tell: Imposes information-flow levels and properties.
  • Program safety. Tell: Is broader than HRU right leakage.

References

  • Frozen Wikipedia discovery revision: https://en.wikipedia.org/wiki/HRU_(security) (revision 1351364819).

The frozen Wikipedia revision is discovery provenance. The retained source set was reviewed for identity, formal or operational relation, and scope. The encyclopedia's structural synthesis is bounded to those claims; a thin authority surface is recorded as a nonblocking source-strengthening repair rather than concealed.