The Shadow Knows: Refinement and security in sequential programs
The Shadow Knows: Refinement and security in sequential programs
复制标题
影子知道:顺序程序的细化和安全性
DOI:
10.1016/j.scico.2007.09.003
复制
发表时间:
2009
期刊:
影响因子:
--
通讯作者:
Carroll Morgan
中科院分区:
文献类型:
--
作者:
Carroll Morgan
Stepwise refinement is a crucial conceptual tool for system development, encouraging program construction via a number of separate correctness-preserving stages which ideally can be understood in isolation. A crucial conceptual component of security is an adversary’s ignorance of concealed information. We suggest a novel method of combining these two ideas. Our suggestion is based on a mathematical definition of “ignorance-preserving” refinement that extends classical refinement by limiting an adversary’s access to concealed information: moving from specification to implementation should never increase that access. The novelty is the way we achieve this in the context of sequential programs. Specifically we give an operational model (and detailed justification for it), a basic sequential programming language and its operational semantics in that model, a “logic of ignorance” interpreted over the same model, then a program-logical semantics bringing those together — and finally we use the logic to establish, via refinement, the correctness of a real (though small) protocol: Rivest’s Oblivious Transfer. A previous report⋆treated Chaum’s Dining Cryptographers similarly. In passing we solve the Refinement Paradox for sequential programs.