A comparison of semantic models for intransitive noninterference⋆
نویسنده
چکیده
Noninterference is a notion of information flow security, originally defined for transitive information flow policies. A number of different definitions of noninterference have been proposed for intransitive policies. These definitions are stated with respect to several different semantic models, including state machines with observations on states, state machines with outputs associated to actions, and process algebras. The paper studies the relationship between these definitions and models. Several mappings are defined that transform one semantic model into another, and the correspondences between the definitions under these mappings are precisely characterized. In particular, the paper considers definitions of intransitive noninterference due to Haigh and Young (1987), Roscoe and Goldsmith (1999) and van der Meyden (2007).
منابع مشابه
Noninterference , Transitivity , and Channel - Control Security Policies 1
We consider noninterference formulations of security policies [7] in which the “interferes” relation is intransitive. Such policies provide a formal basis for several real security concerns, such as channel control [17, 18], and assured pipelines [4]. We show that the appropriate formulation of noninterference for the intransitive case is that developed by Haigh and Young for “multidomain secur...
متن کاملWhat , Indeed , is Intransitive Noninterference ? ( Preliminary Report ) ⋆
This paper argues that Haigh and Young’s definition of noninterference for intransitive security policies admits information flows that are not in accordance with the intuitions it seeks to formalise. Several alternative definitions are discussed, which are shown to be equivalent to the classical definition of noninterference with respect to transitive policies. Rushby’s unwinding conditions fo...
متن کاملWhat, Indeed, Is Intransitive Noninterference?
This paper argues that Haigh and Young’s definition of noninterference for intransitive security policies admits information flows that are not in accordance with the intuitions it seeks to formalise. Several alternative definitions are discussed, which are shown to be equivalent to the classical definition of noninterference with respect to transitive policies. Rushby’s unwinding conditions fo...
متن کاملUnwinding Conditional Noninterference
Noninterference provides a control over information flow in a system for ensuring confidentiality and integrity properties. In the literature this notion has been well studied as transitive noninterference and intransitive noninterference. In this paper we define a framework on the notion of conditional noninterference, which allows to specify information flow policies based on the semantics of...
متن کاملA Comparison of Semantic Models for Noninterference
The literature on definitions of security based on causalitylike notions such as noninterference has used several distinct semantic models for systems. Early work was based on state-machine and traceset definitions; more recent work has dealt with definitions of security in two distinct process algebraic settings. Comparisons between the definitions has been carried out mainly within semantic f...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007