首页> 外文会议>IEEE Computer Security Foundations Symposium >Reconciling progress-insensitive noninterference and declassification
【24h】

Reconciling progress-insensitive noninterference and declassification

机译:调和对进度不敏感的不干扰和解密

获取原文

摘要

Practitioners of secure information flow often face a design challenge: what is the right semantic treatment of leaks via termination? On the one hand, the potential harm of untrusted code calls for strong progress-sensitive security. On the other hand, when the code is trusted to not aggressively exploit termination channels, practical concerns, such as permissiveness of the enforcement, make a case for settling for weaker, progress-insensitive security. This binary situation, however, provides no suitable middle point for systems that mix trusted and untrusted code. This paper connects the two extremes by reframing progress-insensitivity as a particular form of declassification. Our novel semantic condition reconciles progress-insensitive security as a declassification bound on the so-called progress knowledge in an otherwise progress or timing sensitive setting. We show how the new condition can be soundly enforced using a mostly standard information-flow monitor. We believe that the connection established in this work will enable other applications of ideas from the literature on declassification to progress-insensitivity.
机译:安全信息流的从业者经常面临设计挑战:通过终止对泄漏进行正确的语义处理是什么?一方面,不可信代码的潜在危害要求强大的对进度敏感的安全性。另一方面,当信任该代码不会主动使用终止通道时,实际的问题(例如强制执行)将为解决较弱的,对进度不敏感的安全性奠定基础。但是,这种二进制情况无法为混合受信任和不受信任代码的系统提供合适的中间点。本文通过将对进展的不敏感性重新定义为解密的一种特殊形式,将两个极端联系起来。我们新颖的语义条件将对进度不敏感的安全性作为调解,作为在其他对进度或时间敏感的环境中对所谓的进度知识的限制。我们展示了如何使用大多数标准的信息流监视器合理地实施新条件。我们认为,这项工作中建立的联系将使从解密到消极进展的文献中的思想的其他应用成为可能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号