Modular and Constraint-Based Information Flow Inference for an Object-Oriented Language
Modular and Constraint-Based Information Flow Inference for an Object-Oriented Language
复制标题
面向对象语言的模块化和基于约束的信息流推理
DOI:
10.1007/978-3-540-27864-1_9
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
D. Naumann
中科院分区:
文献类型:
--
作者:
Qi Sun;A. Banerjee;D. Naumann
This paper addresses the problem of checking programs written in an object-oriented language to ensure that they satisfy the information flow policies, confidentiality and integrity. Policy is specified using security types. An algorithm that infers such security types in a modular manner is presented. The specification of the algorithm involves inference for libraries. Library classes and methods maybe parameterized by security levels. It is shown how modular inference is achieved in the presence of method inheritance and override. Soundness and completeness theorems for the inference algorithm are given.