Data-Dependent Confidentiality in DCR Graphs

被引:0
|
作者
Geraldo, Eduardo [1 ]
Seco, Joao Costa [1 ]
Hildebrandt, Thomas [2 ]
机构
[1] NOVA Univ Lisbon, NOVA LINCS, Caparica, Portugal
[2] Univ Copenhagen, Copenhagen, Denmark
关键词
Information Flow Control; Privacy; Software Security; Business Processes; DCR Graphs; Security Monitoring; INFORMATION-FLOW; NONINTERFERENCE;
D O I
10.1145/3610612.3610619
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We present DCRSec, a confidentially aware declarative process language with data that employs data-dependent security levels and an information flow monitor that prevents the violation of information flow policies. Data-dependent security levels have been used to shape precise information flow policies and properly identify security compartments. We use an illustrative example to show that it also models process instances in a flexible but precise way. The semantics of the language is based on a version of the Dynamic Condition Response Graph language, which allows for declaring data-aware, event-based processes with finitary and infinitary computations subject to liveness properties and dynamically spawned sub-processes. The key technical contribution is to provide a termination-insensitive information flow monitor and prove non-interference, a soundness property, and transparency in all traces of DCRSec processes.
引用
收藏
页数:13
相关论文
共 50 条
  • [21] MULTIVARIATE HISTOGRAMS WITH DATA-DEPENDENT PARTITIONS
    Klemela, Jussi
    [J]. STATISTICA SINICA, 2009, 19 (01) : 159 - 176
  • [22] A cipher based on data-dependent permutations
    A. A. Moldovyan
    N. A. Moldovyan
    [J]. Journal of Cryptology, 2002, 15 : 61 - 72
  • [23] DATA-DEPENDENT PERMUTATION TECHNIQUES FOR THE ANALYSIS OF ECOLOGICAL DATA
    BIONDINI, ME
    MIELKE, PW
    BERRY, KJ
    [J]. VEGETATIO, 1988, 75 (03): : 161 - 168
  • [24] Data-dependent kernel machines for Microarray data classification
    Xiong, Huilin
    Zhang, Ya
    Chen, Xue-Wen
    [J]. IEEE-ACM TRANSACTIONS ON COMPUTATIONAL BIOLOGY AND BIOINFORMATICS, 2007, 4 (04) : 583 - 595
  • [25] Extending the data parallel paradigm with data-dependent operators
    Biancardi, A
    Mérigot, A
    [J]. PARALLEL COMPUTING, 2002, 28 (7-8) : 995 - 1021
  • [26] Data detection and coding for data-dependent superimposed training
    Wang, Ping
    Fan, Pingzhi
    Yuan, Weina
    Darnell, Michael
    [J]. IET SIGNAL PROCESSING, 2014, 8 (02) : 138 - 145
  • [27] First CPIR Protocol with Data-Dependent Computation
    Lipmaa, Helger
    [J]. INFORMATION SECURITY AND CRYPTOLOGY - ISISC 2009, 2010, 5984 : 193 - 210
  • [28] Switchable data-dependent operations: New designs
    Moldovyan, N. A.
    Moldovyan, A. A.
    [J]. INTERNATIONAL E-CONFERENCE ON COMPUTER SCIENCE 2005, 2005, 2 : 174 - 177
  • [29] Data-dependent reduced-dimension STAP
    Zhang, Wei
    Han, Minghua
    He, Zishu
    Li, Huiyong
    [J]. IET RADAR SONAR AND NAVIGATION, 2019, 13 (08): : 1287 - 1294
  • [30] A Low-Complexity Data-Dependent Beamformer
    Synnevag, Johan-Fredrik
    Austeng, Andreas
    Holm, Sverre
    [J]. IEEE TRANSACTIONS ON ULTRASONICS FERROELECTRICS AND FREQUENCY CONTROL, 2011, 58 (02) : 281 - 289