Input: the model (BLP or BIBA), the number of levels and their names from lowest to highest, then lines subject NAME LEVEL, object NAME LEVEL, and requests SUBJECT read|write OBJECT.
Rules:
- BLP (confidentiality): read allowed iff level(subject) ≥ level(object) ("no read up"); write allowed iff level(subject) ≤ level(object) ("no write down").
- BIBA (integrity): read allowed iff level(subject) ≤ level(object) ("no read down"); write allowed iff level(subject) ≥ level(object) ("no write up").
Print analyst (Confidential) read exams (Secret): DENIED by no read up or … ALLOWED, and finally BLP: a of n requests allowed.