Harrison–Ruzzo–Ullman Security Model¶
An access-control transition model of subjects, objects, rights-valued matrix cells, and guarded commands whose general new-right leakage safety problem is undecidable.
Core Idea¶
HRU gives access control an operational semantics. A configuration consists of subjects, objects, and an access matrix; guarded commands atomically add or remove rights and create or delete subjects and objects.
Safety is a reachability property, not a snapshot check: can some legal command sequence cause a selected right to appear in a cell where it was initially absent? Harrison, Ruzzo, and Ullman showed that this question is undecidable for the general model, while restricted command forms can be decidable.
Structural Signature¶
Sig role-phrases:
- Subjects — Occupy matrix rows and may execute commands. It is active entities. Counterfactual: Objects alone cannot request state changes.
- Objects — Occupy columns and receive controlled operations. It is resource entities. Counterfactual: Unmodeled resources have no rights state.
- Access-right matrix — Maps each subject–object pair to a set of rights. It is state representation. Counterfactual: A role list without cell structure is another model.
- Guarded commands — Specify enabled transformations using rights preconditions. It is transition rules. Counterfactual: Arbitrary state change defeats the protection system definition.
- Primitive updates — Enter/delete rights and create/delete subjects or objects. It is state mutation. Counterfactual: Policy prose without primitives cannot support reachability analysis.
- Safety query — Asks whether a specified right can leak to a new cell along any execution. It is verification target. Counterfactual: Checking only the initial matrix misses reachability.
What It Is Not¶
- It is not merely a static permission table.
- Safety here is a specific right-leakage predicate.
- Undecidability does not make every restricted instance unanalyzable.
- The model does not by itself prove implementation security.
- Closest near-miss. The Graham–Denning model also uses access matrices and transformations; HRU emphasizes the formal command system and the general undecidability boundary for safety.
Scope of Application¶
- Access-control theory. Formalizes administrative rights changes.
- Operating-system security. Models subjects, objects, and permissions.
- Formal verification. Locates decidability boundaries.
- Security-policy design. Shows costs of expressive delegation.
Clarity¶
State initial subjects, objects, rights, full matrix, command parameters, guards, primitive effects, atomicity, entity-creation bounds, queried right and cell condition, and any restriction used for decidability.
Manages Complexity¶
HRU reduces protection administration to reachability over matrix-transforming commands and exposes how modest operational expressiveness yields an unbounded verification problem.
Abstract Reasoning¶
- Encode the initial access configuration.
- Translate each administrative action into guards and primitives.
- Define the exact leakage predicate.
- Determine whether the model lies in a decidable restriction.
- Use sound analysis without claiming a general algorithm where none exists.
Knowledge Transfer¶
HRU conclusions transfer only when another system's principals, resources, rights, commands, atomicity, creation power, and safety predicate are faithfully encoded; RBAC or capability semantics require explicit mapping.
Examples¶
Canonical¶
From an initial matrix, a guarded command checks an owner right and atomically enters read in another subject's file cell; safety asks whether any sequence can place a chosen right in a cell that initially lacked it.
Mapped back: subjects → grantor and grantee; object → file; matrix → rights sets; guard → owner present; mutation → enter read; query → new-right reachability.
Applied / In Practice¶
Listing who currently has read permission is a static audit, not an HRU safety analysis unless commands and future reachability are modeled.
Mapped back: matrix snapshot → present; commands → absent; reachability → absent.
Structural Tensions¶
T1 — Expressive Administration versus Decidable Verification. Rich commands model realistic delegation but make general safety undecidable.
Diagnostic: What syntactic restriction recovers a decision procedure?
T2 — Finite Current State versus Unbounded Evolution. Each configuration is finite while creation and arbitrary sequences make reachability unbounded.
Diagnostic: Which bounds on entities or operations are maintained?
Structural–Framed Character¶
HRU is structural as access-matrix reachability and security-framed by rights, commands, and leakage.
Structural Core vs. Domain Accent¶
The core is state carrier, guarded transitions, and reachability query. Security theory supplies principals, access rights, safety interpretation, and undecidability result.
Instantiates / Related Primes¶
This entry presupposes Access Control.
-
Approved root. No reviewed parent entails this protection-system transition model.
-
Related — access matrix, Graham–Denning model, safety property, reachability, and undecidability. They provide representation, predecessor, query class, method, and limit.
Relationships to Other Abstractions¶
Current abstraction Harrison–Ruzzo–Ullman Security Model Domain-specific
Parents (1) — more general patterns this builds on
-
Harrison–Ruzzo–Ullman Security Model presupposes Access Control Prime
Harrison–Ruzzo–Ullman Security Model presupposes Access Control because the model represents subjects, objects, rights, and guarded access-control transitions.Every reviewed Harrison–Ruzzo–Ullman Security Model instance depends on the parent role: the model represents subjects, objects, rights, and guarded access-control transitions. Removing that role makes the frozen child identity undefined or changes it into a different abstraction. Access Control can occur without Harrison–Ruzzo–Ullman Security Model, so the relation is dependency rather than subsumption.
Hierarchy paths (3) — routes to 3 parentless roots
- Harrison–Ruzzo–Ullman Security Model → Access Control → Authority
- Harrison–Ruzzo–Ullman Security Model → Access Control → Boundary
- Harrison–Ruzzo–Ullman Security Model → Access Control → Constraint
Neighborhood in Abstraction Space¶
Harrison–Ruzzo–Ullman Security Model sits in a crowded region of the domain-specific corpus (30th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.
Family — Formal Systems & Discrete Structures (18 abstractions)
Nearest neighbors
- Bell–LaPadula Model — 0.91
- Protection Ring — 0.89
- Role Class Model — 0.89
- Ambient Authority — 0.88
- Generalized Büchi Automaton — 0.88
Computed from structural-signature embeddings · 2026-10-08
Not to Be Confused With¶
- Static access matrix. Tell: Has no transition commands or reachability.
- Role-based access control. Tell: Organizes permissions through roles rather than HRU cells directly.
- Bell–LaPadula. Tell: Imposes information-flow levels and properties.
- Program safety. Tell: Is broader than HRU right leakage.
References¶
- Frozen Wikipedia discovery revision: https://en.wikipedia.org/wiki/HRU_(security) (revision 1351364819).
The frozen Wikipedia revision is discovery provenance. The retained source set was reviewed for identity, formal or operational relation, and scope. The encyclopedia's structural synthesis is bounded to those claims; a thin authority surface is recorded as a nonblocking source-strengthening repair rather than concealed.