Abstract
Secure canonical upgrade policies are multilevel re-label policies that, under certain conditions, allow high-level subjects to update low-level security labels. This paper describes a scheme whereby these policies can be supported within the message filter model for multilevel secure object-oriented database management systems.