Enforcing robust declassification

Enforcing robust declassification
复制标题

强制解密

DOI:
10.1109/csfw.2004.9
复制
发表时间:
2004
期刊:
Proceedings. 17th IEEE Computer Security Foundations Workshop, 2004.
影响因子:
--
通讯作者:
Steve Zdancewic
Steve Zdancewic
中科院分区:
--
文献类型:
--
作者:
A. Myers;A. Sabelfeld;Steve Zdancewic

文献摘要

被引文献

相似文献

不干扰要求在给定系统中没有从敏感数据到公共数据的信息流。然而,许多系统执行敏感信息的故意释放作为其正确功能的一部分,因此违反了不干涉。为了控制信息流,同时允许有意的信息发布,一些系统具有降级或解密机制。这种机制的一个主要危险是,它可能会导致无意的信息发布。本文表明,鲁棒性可以用来描述程序中的解密机制不能被攻击者利用释放更多的信息比预期的。它描述了一种简单的方法,通过基于类型的编译时程序分析来证明这种鲁棒性。本文还提出了一个泛化的鲁棒性,支持升级(背书)数据完整性。
Noninterference requires that there is no information flow from sensitive to public data in a given system. However, many systems perform intentional release of sensitive information as part of their correct functioning and therefore violate noninterference. To control information flow while permitting intentional information release, some systems have a downgrading or declassification mechanism. A major danger of such a mechanism is that it may cause unintentional information release. This paper shows that a robustness property can be used to characterize programs in which declassification mechanisms cannot be exploited by attackers to release more information than intended. It describes a simple way to provably enforce this robustness property through a type-based compile-time program analysis. The paper also presents a generalization of robustness that supports upgrading (endorsing) data integrity.