Harrison–Ruzzo–Ullman Security Model¶
An access-control transition model of subjects, objects, rights-valued matrix cells, and guarded commands whose general new-right leakage safety problem is undecidable.
Core Idea¶
HRU gives access control an operational semantics. A configuration consists of subjects, objects, and an access matrix; guarded commands atomically add or remove rights and create or delete subjects and objects.
Safety is a reachability property, not a snapshot check: can some legal command sequence cause a selected right to appear in a cell where it was initially absent? Harrison, Ruzzo, and Ullman showed that this question is undecidable for the general model, while restricted command forms can be decidable.
Scope of Application¶
- Access-control theory. Formalizes administrative rights changes.
- Operating-system security. Models subjects, objects, and permissions.
- Formal verification. Locates decidability boundaries.
- Security-policy design. Shows costs of expressive delegation.
Clarity¶
State initial subjects, objects, rights, full matrix, command parameters, guards, primitive effects, atomicity, entity-creation bounds, queried right and cell condition, and any restriction used for decidability. Inclusion test: Require HRU-style subject/object sets, rights-valued access matrix, guarded commands built from allowed primitives, an initial configuration, and a right-leakage reachability query. Exclusion test: Exclude static access-control matrices with no command semantics, confidentiality claims unrelated to rights reachability, and claims that all useful HRU safety questions are decidable. Nearest boundary: The Graham–Denning model also uses access matrices and transformations; HRU emphasizes the formal command system and the general undecidability boundary for safety. Exit condition: Changing the state representation or safety predicate can yield another access-control model; restricting command primitives changes the decidability result and must be named. Common misclassifications: It is not merely a static permission table. Safety here is a specific right-leakage predicate. Undecidability does not make every restricted instance unanalyzable. The model does not by itself prove implementation security. Nearest named distinctions: Static access matrix: Has no transition commands or reachability. Role-based access control: Organizes permissions through roles rather than HRU cells directly. Bell–LaPadula: Imposes information-flow levels and properties. Program safety: Is broader than HRU right leakage.
Manages Complexity¶
HRU reduces protection administration to reachability over matrix-transforming commands and exposes how modest operational expressiveness yields an unbounded verification problem.
Abstract Reasoning¶
- Encode the initial access configuration.
- Translate each administrative action into guards and primitives.
- Define the exact leakage predicate.
- Determine whether the model lies in a decidable restriction.
- Use sound analysis without claiming a general algorithm where none exists.
Knowledge Transfer¶
HRU conclusions transfer only when another system's principals, resources, rights, commands, atomicity, creation power, and safety predicate are faithfully encoded; RBAC or capability semantics require explicit mapping.
Relationships to Other Abstractions¶
Current abstraction Harrison–Ruzzo–Ullman Security Model Domain-specific
Parents (1) — more general patterns this builds on
-
Harrison–Ruzzo–Ullman Security Model presupposes Access Control Prime
Harrison–Ruzzo–Ullman Security Model presupposes Access Control because the model represents subjects, objects, rights, and guarded access-control transitions.
Hierarchy paths (3) — routes to 3 parentless roots
- Harrison–Ruzzo–Ullman Security Model → Access Control → Authority
- Harrison–Ruzzo–Ullman Security Model → Access Control → Boundary
- Harrison–Ruzzo–Ullman Security Model → Access Control → Constraint
Neighborhood in Abstraction Space¶
Harrison–Ruzzo–Ullman Security Model sits in a crowded region of the domain-specific corpus (30th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.
Family — Formal Systems & Discrete Structures (18 abstractions)
Nearest neighbors
- Bell–LaPadula Model — 0.91
- Protection Ring — 0.89
- Role Class Model — 0.89
- Ambient Authority — 0.88
- Generalized Büchi Automaton — 0.88
Computed from structural-signature embeddings · 2026-10-08