TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. Assumptions and guarantees for compositional noninterference
 
Options

Assumptions and guarantees for compositional noninterference

Publikationstyp
Conference Paper
Date Issued
2011-06
Sprache
English
Author(s)
Mantel, Heiko 
Sands, David  
Sudbrock, Henning  
TORE-URI
http://hdl.handle.net/11420/13885
Start Page
218
End Page
232
Article Number
5992165
Citation
Proceedings - IEEE Computer Security Foundations Symposium: 5992165, 218-232 (2011-09-16)
Contribution to Conference
24th Computer Security Foundations Symposium, CSF 2011  
Publisher DOI
10.1109/CSF.2011.22
Scopus ID
2-s2.0-80052650505
Publisher
IEEE
The idea of building secure systems by plugging together "secure" components is appealing, but this requires a definition of security which, in addition to taking care of top-level security goals, is strengthened appropriately in order to be compositional. This approach has been previously studied for information-flow security of shared-variable concurrent programs, but the price for compositionality is very high: a thread must be extremely pessimistic about what an environment might do with shared resources. This pessimism leads to many intuitively secure threads being labelled as insecure. Since in practice it is only meaningful to compose threads which follow an agreed protocol for data access, we take advantage of this to develop a more liberal compositional security condition. The idea is to give the security definition access to the intended pattern of data usage, as expressed by assumption-guarantee style conditions associated with each thread. We illustrate the improved precision by developing the first flow-sensitive security type system that provably enforces a noninterference-like property for concurrent programs.
Subjects
Assumption-Guarantee
Compositional Verification
Flow-Sensitivity
Information Flow Security
DDC Class
004: Informatik
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback