Secured Information Flow for Asynchronous Sequential Processes

Electronic Notes in Theoretical Computer Science(2007)

引用 7|浏览0
暂无评分
摘要
We present in this article a precise security model for data confidentiality in the framework of ASP (Asynchronous Sequential Processes). ASP is based on active objects, asynchronous communications, and data-flow synchronizations. We extend it with security levels attached to activities (active objects) and transmitted data. We design a security model that guarantees data confidentiality within an application; this security model takes advantages of both mandatory and discretionary access models. We extend the semantics of ASP with predicate conditions that provide a formal security framework, dynamically checking for unauthorized information flows. As a final result, all authorized communication paths are secure: no disclosure of information can happen. This theoretically-founded contribution may have a strong impact on distributed object-based applications, that are more and more present and confidentiality-demanding on the Internet, it also arises a new issue in data confidentiality: authorization of secured information flow transiting (by the mean of futures) through an unsecured component.
更多
查看译文
关键词
security level,asynchronous sequential processes,security model,secured information flow,distribution,precise security model,futures,data confidentiality,access control,active object,formal security framework,secured information flow transiting,transmitted data,unauthorized information flow,objects,discretionary access model,information flow,asynchronous communication,distributed objects,data flow
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要