首页> 外文期刊>International Journal of Information Security >Dynamic security labels and static information flow control
【24h】

Dynamic security labels and static information flow control

机译:动态安全标签和静态信息流控制

获取原文
获取原文并翻译 | 示例
           

摘要

This paper presents a language in which information flow is securely controlled by a type system, yet the security class of data can vary dynamically. Information flow policies provide the means to express strong security requirements for data confidentiality and integrity. Recent work on security-typed programming languages has shown that information flow can be analyzed statically, ensuring that programs will respect the restrictions placed on data. However, real computing systems have security policies that cannot be determined at the time of program analysis. For example, a file has associated access permissions that cannot be known with certainty until it is opened. Although one security-typed programming language has included support for dynamic security labels, there has been no demonstration that a general mechanism for dynamic labels can securely control information flow. In this paper, we present an expressive language-based mechanism for reasoning about dynamic security labels. The mechanism is formally presented in a core language based on the typed lambda calculus; any well-typed program in this language is secure because it satisfies noninterference.
机译:本文提出了一种语言,其中信息流由类型系统安全地控制,但是数据的安全性类别可以动态变化。信息流策略提供了表达对数据机密性和完整性的严格安全要求的方法。有关安全类型的编程语言的最新工作表明,可以静态地分析信息流,从而确保程序将遵守对数据的限制。但是,实际的计算系统具有在程序分析时无法确定的安全策略。例如,文件具有关联的访问权限,只有在打开文件之前,才能确定该文件的访问权限。尽管一种安全类型的编程语言已包括对动态安全标签的支持,但没有证明动态标签的通用机制可以安全地控制信息流。在本文中,我们提出了一种基于表达语言的机制来对动态安全标签进行推理。该机制以基于类型Lambda演算的核心语言形式正式提出;用这种语言编写的任何类型良好的程序都是安全的,因为它满足无干扰要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号