Abstract :
Research in developing formalisms for secure distributed systems reveals that a graph-theoretic model captures the fundamental notion of trust, while permitting a rigorous and elegant decomposition into lower levels of implementation. With such a model, security labels need be applied to directed edges only, not to events, ports, processes, messages, or whatever. Moreover, the usual concept of "secure state" does not lend itself to defining security in a distributed system, whereas our Model guarantees secure transitions in precisely this context.