• DocumentCode
    2009779
  • Title

    Tractable Enforcement of Declassification Policies

  • Author

    Barthe, Gilles ; Cavadini, Salvador ; Rezk, Tamara

  • fYear
    2008
  • fDate
    23-25 June 2008
  • Firstpage
    83
  • Lastpage
    97
  • Abstract
    Formalizing appropriate information policies that authorize some controlled form of information release, and providing sound analyses for these policies is a necessary step towards practical applications of language-based security. We propose a modular method to enhance non-interference type systems to support controlled forms of information release that combine the what and where dimensions of declassification. As a case study, we derive from earlier work on non-interference type systems new type systems that soundly enforce declassification policies for sequential fragments of the Java Virtual Machine. Our work provides the first modular method to define sound type systems for declassification policies, and the first instance of a sound type system that supports declassification policies for unstructured languages.
  • Keywords
    Computer security; Control systems; Data security; Information analysis; Information security; Java; Virtual machining; declassification; information flow security; type systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Foundations Symposium, 2008. CSF '08. IEEE 21st
  • Conference_Location
    Pittsburgh, PA, USA
  • ISSN
    1940-1434
  • Print_ISBN
    978-0-7695-3182-3
  • Type

    conf

  • DOI
    10.1109/CSF.2008.11
  • Filename
    4556680