Secure Information Flow as a Safety Property

被引:0
|
作者
Boudol, Gerard [1 ]
机构
[1] INRIA, F-06902 Sophia Antipolis, France
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we argue that, in the perspective of developing "security-minded" programming languages, the secure information flow property should be defined (as well as disciplined access) as a standard safety property, based on a notion of a security error, namely that one should not put in a public location a value elaborated using confidential information. We show that this is the property guaranteed by a standard security type system, and that, for a simple language, it is strictly stronger than non-interference. Moreover, we show that this notion of secure information flow allows us to give natural semantics to various security-minded programming constructs, including declassification.
引用
收藏
页码:20 / 34
页数:15
相关论文
共 50 条
  • [1] Secure information flow as a safety problem
    Terauchi, T
    Aiken, A
    [J]. STATIC ANALYSIS, PROCEEDINGS, 2005, 3672 : 352 - 367
  • [2] Secure information flow connections
    Bhardwaj, Chandrika
    Prasad, Sanjiva
    [J]. JOURNAL OF LOGICAL AND ALGEBRAIC METHODS IN PROGRAMMING, 2022, 127
  • [3] Arrows for secure information flow
    Li, Peng
    Zdancewic, Steve
    [J]. THEORETICAL COMPUTER SCIENCE, 2010, 411 (19) : 1974 - 1994
  • [4] Information flow in secure contexts
    Bossi, Annalisa
    Macedonio, Damiano
    Piazza, Carla
    Rossi, Sabina
    [J]. JOURNAL OF COMPUTER SECURITY, 2005, 13 (03) : 391 - 422
  • [5] Information Flow Secure CAmkES
    Goyal, Amit
    Garg, Akshat
    Gour, Digvijaysingh
    Shyamasundar, R. K.
    Sivakumar, G.
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY (IOTBDS), 2021, : 237 - 244
  • [6] Secure information flow and CPS
    Zdancewic, S
    Myers, AC
    [J]. PROGRAMMING LANGUAGES AND SYSTEMS, PROCEEDINGS, 2001, 2028 : 46 - 61
  • [7] Compositionality of Secure Information Flow
    Palamidessi, Catuscia
    [J]. MATHEMATICS OF PROGRAM CONSTRUCTION, PROCEEDINGS, 2010, 6120 : 19 - 19
  • [8] Principles of secure information flow analysis
    Smith, Geoffrey
    [J]. Malware Detection, 2007, : 291 - 307
  • [9] Array operations for secure information flow
    Yao, JB
    Li, JS
    [J]. PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 3884 - 3892
  • [10] SPLinux*: An Information Flow Secure Linux
    Vyas, Parjanya
    Shyamasundar, Rk
    Patil, Bhagyesh
    Borse, Snehal
    Sen, Satyaki
    [J]. 19TH IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS (ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM 2021), 2021, : 1603 - 1612