Chinese Wall Model (Brewer-Nash)
The Brewer-Nash model: access rights change dynamically based on what a user has already accessed, blocking conflicts of interest between competing clients' data.
Full guide: Chinese Wall Model (Brewer-Nash) Explained
The Chinese Wall model, formally Brewer-Nash, exists to prevent conflicts of interest. Picture a consultancy serving two competing banks. Before an analyst opens any file they may access either client. The moment they read Bank A’s data, a wall goes up: Bank B’s dataset, and everything else in that conflict-of-interest class, becomes off limits to them.
The structure has three layers worth keeping straight. Objects are individual files. Company datasets group every object belonging to one organisation. Conflict-of-interest classes group the datasets that compete with each other. Reading is permitted only from a dataset the subject has already entered, or from one whose class the subject has not yet touched.
What makes it unlike the other models
| Model | Decides access from | Permissions change over time? |
|---|---|---|
| Chinese Wall (Brewer-Nash) | The subject’s access history | Yes |
| Bell-LaPadula | Clearance against classification | No |
| Biba | Integrity levels | No |
| Clark-Wilson | A fixed set of access triples | No |
That single Yes is the reason the model is memorable and the reason it is tested. Every other model in this group evaluates a fixed policy, so identical subjects get identical answers. Brewer-Nash is the only one where your own past reads narrow your future ones, which means two analysts on the same grade with the same job title can hold different effective permissions.
It also carries a write rule that is easy to overlook: a subject may write to a dataset only if it can read no dataset in a different company that contains unsanitised information. Without it, two analysts could collude indirectly by using a shared file as a channel between walled clients.
A worked case
An analyst joins an audit practice with three conflict-of-interest classes on the books: retail banks, telecoms, and energy.
On day one every dataset is open. They open Bank A’s file, and Bank B and Bank C close immediately while telecoms and energy remain available. They then open a telecoms client, closing that client’s competitors too. Their access surface is now determined entirely by two historical decisions, and no administrator granted or revoked anything. The wall is a consequence of work done, which is what a partner reviewing independence would actually want.
This is a time-based flavour of separation of duties applied across clients rather than across the steps of one process. The Brewer-Nash guide covers the formal rules.
The source
The model comes from D. F. C. Brewer and M. J. Nash, The Chinese Wall Security Policy, published in the Proceedings of the 1989 IEEE Symposium on Security and Privacy. The authors wrote it for the UK financial sector after regulatory separation requirements made the existing lattice models a poor fit, which is why it reads more like a commercial compliance rule than a military one.
Exam relevance: three trigger phrases point straight here, and questions in this area tend to use one of them rather than naming the model: “conflict of interest”, “Chinese Wall”, and “access depends on previous access”. It is the expected answer for consultancies, law firms and financial institutions handling competing clients. If the scenario’s permissions never change, it is not Brewer-Nash.
Frequently asked questions
- What is the Chinese Wall model?
- The Chinese Wall model, formally Brewer-Nash, prevents conflicts of interest by making access rights depend on access history. Datasets are grouped into conflict-of-interest classes, and once a subject reads from one dataset in a class, every other dataset in that same class becomes unavailable to them. It was designed for financial and professional services firms that advise competing clients from one office.
- Why is Brewer-Nash different from other security models?
- Because its permissions are dynamic. Bell-LaPadula and Biba compare fixed labels, and Clark-Wilson checks a fixed set of access triples, so in each case the same request yields the same answer every time. In Brewer-Nash the answer depends on what the subject has already read, which means two users with identical roles and clearances can have different access purely because of their history.
- How does the Chinese Wall model relate to separation of duties?
- It enforces a comparable idea across client boundaries rather than across process steps. Separation of duties splits one sensitive task among several people so no individual controls it end to end. Brewer-Nash splits the client base so no individual sees both sides of a competitive relationship. Both prevent a single person accumulating a combination of access that is dangerous even though each part is legitimate.