论文标题

安全信息流连接

Secure Information Flow Connections

论文作者

Bhardwaj, Chandrika, Prasad, Sanjiva

论文摘要

Denning的晶格模型通过直观的数学基础提供了安全的信息流分析:晶格排序确定允许的流量。我们研究了如何扩展该框架以支持自主组织之间的信息流,每个组织都采用了可能完全不同的安全晶格和信息流策略。我们提出了一个连接框架,该框架允许不同的组织交换信息,同时保持信息流的安全性及其在制定和维护安全策略方面的自主权。我们的规范框架基于梅尔顿提出的Lagois连接的严格数学框架,以及一个简单的操作模型,用于在域之间传输对象数据。该公式的优点是它是简单,最小,适应性和直观的。我们证明,通过证明拟议的连接保留标准正确性概念,例如非干预,我们的框架在语义上是合理的。然后,我们说明Lagois理论还如何提供一个强大的框架和方法,即使在自主组织之间的信息流有关的信息流程,即使在一个或两个组织更改其安全晶格时,也是如此。组成和分解属性表示支持模块化方法以保护复杂组织中的流动框架。接下来,我们显示该框架自然和保守地扩展到Myers等人的分散标签模型。 - 两个组织的原理层次结构之间的LAGOIS连接自然会引起相应的安全标签晶格之间的Lagois连接,因此扩展了分散模型确保的安全保证,以包含双向跨组织间流。

Denning's lattice model provided secure information flow analyses with an intuitive mathematical foundation: the lattice ordering determines permitted flows. We examine how this framework may be extended to support the flow of information between autonomous organisations, each employing possibly quite different security lattices and information flow policies. We propose a connection framework that permits different organisations to exchange information while maintaining both security of information flow as well as their autonomy in formulating and maintaining security policies. Our prescriptive framework is based on the rigorous mathematical framework of Lagois connections proposed by Melton, together with a simple operational model for transferring object data between domains. The merit of this formulation is that it is simple, minimal, adaptable and intuitive. We show that our framework is semantically sound, by proving that the connections proposed preserve standard correctness notions such as non-interference. We then illustrate how Lagois theory also provides a robust framework and methodology for negotiating and maintaining secure agreements on information flow between autonomous organisations, even when either or both organisations change their security lattices. Composition and decomposition properties indicate support for a modular approach to secure flow frameworks in complex organisations. We next show that this framework extends naturally and conservatively to the Decentralised Labels Model of Myers et al. - a Lagois connection between the hierarchies of principals in two organisations naturally induces a Lagois connection between the corresponding security label lattices, thus extending the security guarantees ensured by the decentralised model to encompass bidirectional inter-organisational flows.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源