Skip to content

Harrison–Ruzzo–Ullman Security Model

An access-control transition model of subjects, objects, rights-valued matrix cells, and guarded commands whose general new-right leakage safety problem is undecidable.

Version
v1 · 2026-09-28 · History
Domain-specific #
9915
Domain group
Applied Sciences & Engineering
Origin domain
Computer Science & Software Engineering
Subdomains
Computer Security, Access Control → Computer Science & Software Engineering
Aliases
HRU Security Model, HRU Model, Harrison Ruzzo Ullman Model

Core Idea

HRU gives access control an operational semantics. A configuration consists of subjects, objects, and an access matrix; guarded commands atomically add or remove rights and create or delete subjects and objects.

Safety is a reachability property, not a snapshot check: can some legal command sequence cause a selected right to appear in a cell where it was initially absent? Harrison, Ruzzo, and Ullman showed that this question is undecidable for the general model, while restricted command forms can be decidable.

Scope of Application

  • Access-control theory. Formalizes administrative rights changes.
  • Operating-system security. Models subjects, objects, and permissions.
  • Formal verification. Locates decidability boundaries.
  • Security-policy design. Shows costs of expressive delegation.

Clarity

State initial subjects, objects, rights, full matrix, command parameters, guards, primitive effects, atomicity, entity-creation bounds, queried right and cell condition, and any restriction used for decidability. Inclusion test: Require HRU-style subject/object sets, rights-valued access matrix, guarded commands built from allowed primitives, an initial configuration, and a right-leakage reachability query. Exclusion test: Exclude static access-control matrices with no command semantics, confidentiality claims unrelated to rights reachability, and claims that all useful HRU safety questions are decidable. Nearest boundary: The Graham–Denning model also uses access matrices and transformations; HRU emphasizes the formal command system and the general undecidability boundary for safety. Exit condition: Changing the state representation or safety predicate can yield another access-control model; restricting command primitives changes the decidability result and must be named. Common misclassifications: It is not merely a static permission table. Safety here is a specific right-leakage predicate. Undecidability does not make every restricted instance unanalyzable. The model does not by itself prove implementation security. Nearest named distinctions: Static access matrix: Has no transition commands or reachability. Role-based access control: Organizes permissions through roles rather than HRU cells directly. Bell–LaPadula: Imposes information-flow levels and properties. Program safety: Is broader than HRU right leakage.

Manages Complexity

HRU reduces protection administration to reachability over matrix-transforming commands and exposes how modest operational expressiveness yields an unbounded verification problem.

Abstract Reasoning

  1. Encode the initial access configuration.
  2. Translate each administrative action into guards and primitives.
  3. Define the exact leakage predicate.
  4. Determine whether the model lies in a decidable restriction.
  5. Use sound analysis without claiming a general algorithm where none exists.

Knowledge Transfer

HRU conclusions transfer only when another system's principals, resources, rights, commands, atomicity, creation power, and safety predicate are faithfully encoded; RBAC or capability semantics require explicit mapping.

Relationships to Other Abstractions

Local relationship map for Harrison–Ruzzo–Ullman Security ModelParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Harrison–Ruzzo–UllmanSecurity ModelDOMAINPrime abstraction: Access Control — presupposesAccess ControlPRIME

Current abstraction Harrison–Ruzzo–Ullman Security Model Domain-specific

Parents (1) — more general patterns this builds on

  • Harrison–Ruzzo–Ullman Security Model presupposes Access Control Prime

    Harrison–Ruzzo–Ullman Security Model presupposes Access Control because the model represents subjects, objects, rights, and guarded access-control transitions.

Hierarchy paths (3) — routes to 3 parentless roots

Neighborhood in Abstraction Space

Harrison–Ruzzo–Ullman Security Model sits in a crowded region of the domain-specific corpus (30th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.

Family — Formal Systems & Discrete Structures (18 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08