Fabric: Building open distributed systems securely by construction

Fabric: Building open distributed systems securely by construction
复制标题

Fabric:通过构建安全地构建开放的分布式系统

DOI:
10.3233/jcs-15805
复制
发表时间:
2017
期刊:
J. Comput. Secur.
影响因子:
--
通讯作者:
A. Myers
A. Myers
中科院分区:
--
文献类型:
--
作者:
Jed Liu;Owen Arden;Michael D. George;A. Myers

文献摘要

被引文献

相似文献

分布式信息系统在现代计算中很普遍,但很难安全地构建。因为系统通常跨越信任域,所以主机节点共享不同可信度的数据和代码。现代系统通常是开放和可扩展的,这使得安全性更难推理。不幸的是,软件构造的标准方法并不能帮助程序员确保他们的软件是安全的。Fabric是一种系统和语言,用于构建开放的、分布式的、可扩展的信息系统,这些系统和语言通过构造而安全。Fabric是一个分散的系统,允许节点安全地共享数据和代码,尽管相互不信任。所有资源都标有机密性和完整性策略,这些策略通过编译时和运行时机制的组合来实施。Fabric语言提供了一个高级但功能强大的计算模型。所有资源在语言中都是对象,代码和数据的分发和持久化对程序员来说基本上是透明的。Fabric支持数据传送和查询/RPC计算风格:计算和信息都可以在节点之间移动。乐观的嵌套事务确保了所有对象和节点之间的一致性。Fabric程序可以跨信任域安全地共享移动的代码,从而实现代码的更多重用和演进,并支持在其他分布式系统中不可能实现的新型安全应用程序。使用Fabric构建的应用程序的结果表明,Fabric在提供一个干净、简洁、功能强大的编程模型的同时,还具有很好的性能。一个开源原型可供下载。
Distributed information systems are prevalent in modern computing but difficult to build securely. Because systems commonly span domains of trust, host nodes share data and code of varying degrees of trustworthiness. Modern systems are often open and extensible, making security even harder to reason about. Unfortunately, standard methods for software construction do not help programmers enough with ensuring their software is secure. Fabric is a system and language for building open, distributed, extensible information systems that are secure by construction. Fabric is a decentralized system that allows nodes to securely share both data and code despite mutual distrust. All resources are labeled with confidentiality and integrity policies that are enforced through a combination of compile-time and run-time mechanisms. The Fabric language offers a high-level but powerful model of computation. All resources appear as objects in the language, and the distribution and persistence of code and data are largely transparent to programmers. Fabric supports both data-shipping and query/RPC styles of computation: computation and information can both move between nodes. Optimistic, nested transactions ensure consistency across all objects and nodes. Fabric programs can securely share mobile code across trust domains, enabling more reuse and evolution of code and supporting new kinds of secure applications not possible in other distributed systems. Results from applications built using Fabric suggest that Fabric enforces strong security while offering a clean, concise, powerful programming model with good performance. An open-source prototype is available for download.