Encoding information flow in Haskell
Encoding information flow in Haskell
复制标题
Haskell 中的信息流编码
DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
Steve Zdancewic
中科院分区:
文献类型:
--
作者:
Peng Li;Steve Zdancewic
This paper presents an embedded security sublanguage for enforcing information-flow policies in the standard Haskell programming language. The sublanguage provides useful information-flow control mechanisms including dynamic security lattices, run-time code privileges and declassification, without modifying the base language. This design avoids the redundant work of producing new languages, lowers the threshold for adopting security-typed languages, and also provides great flexibility and modularity for using security-policy frameworks. The embedded security sublanguage is designed using a standard combinator interface called arrows. Computations constructed in the sublanguage have static and explicit control-flow components, making it possible to implement information-flow control using static-analysis techniques at run time, while providing strong security guarantees. This paper presents a concrete Haskell implementation and an example application demonstrating the proposed techniques