Title :
A Protocol for Releasing Purpose Marks to Prevent Illegal Information Flow
Author :
Enokido, Tomoya ; Deen, S. Misbah ; Takizawa, Makoto
Author_Institution :
Rissho Univ., Tokyo
Abstract :
A transaction is assigned with a purpose which is a collection of roles. Suppose a transaction T1 writes an object o2 after reading an object o1 and then another transaction T2 reads the object o2 and writes an object o3. Here, data in the object o1 might flow into o3 via o2. Unless T2 is granted a read access right of the object o1, illegal information flow occur. In order to prevent the illegal information flow, T1 marks the object o2 with the purpose of T1. T2 cannot read o2 unless the purpose of T2 includes a read right of o1. In result, the throughput is degraded. Objects whose information may flow into an object o are source objects of o. An object is timed out if it takes some time units after the object is lastly written. While there occur no illegal information flow in our purpose marking (PM)protocol, transactions which imply illegal information flow are aborted. We evaluate the PM protocol in terms of how many transactions are aborted.
Keywords :
authorisation; protocols; illegal information flow prevention; purpose marking protocol; role-based access control; transaction; Access control; Access protocols; Degradation; Permission; Throughput; Information Flow; Purpose-based marking protocol; Role-based access control;
Conference_Titel :
Advanced Information Networking and Applications, 2009. AINA '09. International Conference on
Conference_Location :
Bradford
Print_ISBN :
978-1-4244-4000-9
Electronic_ISBN :
1550-445X
DOI :
10.1109/AINA.2009.101