DocumentCode
3255760
Title
Updatable Security Views
Author
Foster, J. Nathan ; Pierce, China C. ; Zdancewic, Steve
Author_Institution
Univ. of Pennsylvania, Philadelphia, PA, USA
fYear
2009
fDate
8-10 July 2009
Firstpage
60
Lastpage
74
Abstract
Security views are a flexible and effective mechanism for controlling access to confidential information. Rather than allowing untrusted users to access source data directly, they are instead provided with are restricted view, from which all confidential information has been removed. The program that generates the view effectively embodies a confidentiality policy for the underlying source data. However, this approach has a significant drawback: it prevents users from updating the data in the view. To address the "view update problem" in general, a number of bidirectional languages have been proposed. Programs in these languages - often called lenses - can be run in two directions: read from left to right, they map sources to views; from right to left,they map updated views back to updated sources. However, existing bidirectional languages do not deal adequately with security. In particular, they do not provide a way to ensure the integrity of source data as it is manipulated by untrusted users of the view. We propose a novel framework of secure lenses that addresses these shortcomings. We enrich the types of basic lenses with equivalence relations capturing notions of confidentiality and integrity, and formulate the essential security conditions as non-interference properties. We then instantiate this framework in the domain of string transformations, developing syntax for bidirectional string combinators with security-annotated regular expressions as their types.
Keywords
authorisation; formal languages; access control; bidirectional language; bidirectional string combinator; confidential information; confidentiality policy; noninterference property; secure lenses; security views; security-annotated regular expression; source data access; view update problem; Acoustical engineering; Communication system security; Computer science; Computer security; Credit cards; Information analysis; Information security; Java; Monitoring; Remuneration; Security views; confidentiality; information flow; integrity; lenses; regular types; view update;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Security Foundations Symposium, 2009. CSF '09. 22nd IEEE
Conference_Location
Port Jefferson, NY
ISSN
1940-1434
Print_ISBN
978-0-7695-3712-2
Type
conf
DOI
10.1109/CSF.2009.25
Filename
5230487
Link To Document