Formal Aspects of Computing Architectural refinement and notions of intransitive noninterference

Formal Aspects of Computing Architectural refinement and notions of intransitive noninterference
复制标题

计算的形式方面 架构细化和不及物不干涉的概念

DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
R. V. D. Meyden
R. V. D. Meyden
中科院分区:
--
文献类型:
--
作者:
R. V. D. Meyden

文献摘要

被引文献

相似文献

本文讨论了指定系统组件和它们之间允许的信息流的体系结构设计。在系统开发的过程中,人们可以通过将组件视为由子组件组成,并指定这些子组件和设计中的其他组件之间允许的信息流来细化这样的设计。本文针对信息流策略的一系列不同语义研究了这些改进的可靠性,包括Goguen和Meseguer的基于清洗的定义,Haigh和Young的基于不可传递的清洗的定义,以及一些最近由van der Meyden定义的TA-security, to -security和ITO-security的概念。结果表明,所有这些定义都支持体系结构精化的可靠性,无论是对于系统的状态模型还是操作观察模型。还研究了减少观测信息内容的系统精化概念。改进保留了弱访问控制结构,这是一种保证数据交换安全的实现机制。
This paper deals with architectural designs that specify components of a system and the permitted flows of information between them. In the process of systems development, one might refine such a design by viewing a component as being composed of subcomponents, and specifying permitted flows of information between these subcomponents and others in the design. The paper studies the soundness of such refinements with respect to a spectrum of different semantics for information flow policies, including Goguen and Meseguer’s purge-based definition, Haigh and Young’s intransitive purge-based definition, and some more recent notions TA-security, TO-security and ITO-security defined by van der Meyden. It is shown that all these definitions support the soundness of architectural refinement, for both a stateand an action-observed model of systems. A notion of systems refinement in which the information content of observations is reduced is also studied. It is also shown that refinement preserves weak access control structure, an implementation mechanism that ensures TA-security.