DocumentCode
2009779
Title
Tractable Enforcement of Declassification Policies
Author
Barthe, Gilles ; Cavadini, Salvador ; Rezk, Tamara
fYear
2008
fDate
23-25 June 2008
Firstpage
83
Lastpage
97
Abstract
Formalizing appropriate information policies that authorize some controlled form of information release, and providing sound analyses for these policies is a necessary step towards practical applications of language-based security. We propose a modular method to enhance non-interference type systems to support controlled forms of information release that combine the what and where dimensions of declassification. As a case study, we derive from earlier work on non-interference type systems new type systems that soundly enforce declassification policies for sequential fragments of the Java Virtual Machine. Our work provides the first modular method to define sound type systems for declassification policies, and the first instance of a sound type system that supports declassification policies for unstructured languages.
Keywords
Computer security; Control systems; Data security; Information analysis; Information security; Java; Virtual machining; declassification; information flow security; type systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Security Foundations Symposium, 2008. CSF '08. IEEE 21st
Conference_Location
Pittsburgh, PA, USA
ISSN
1940-1434
Print_ISBN
978-0-7695-3182-3
Type
conf
DOI
10.1109/CSF.2008.11
Filename
4556680
Link To Document