Only Connect, Securely - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Only Connect, Securely

Chandrika Bhardwaj
  • Fonction : Auteur
  • PersonId : 1055868
Sanjiva Prasad
  • Fonction : Auteur
  • PersonId : 1055869

Résumé

The lattice model proposed by Denning in her seminal work provided secure information flow analyses with an intuitive and uniform mathematical foundation. Different organisations, however, may employ quite different security lattices. In this paper, we propose a connection framework that permits different organisations to exchange information while maintaining both security of information flow as well as their autonomy in formulating and maintaining security policies. Our prescriptive framework is based on the rigorous mathematical framework of Lagois connections given by Melton, together with a simple operational model for transferring object data between domains. The merit of this formulation is that it is simple, minimal, adaptable and intuitive, and provides a formal framework for establishing secure information flow across autonomous interacting organisations. We show that our framework is semantically sound, by proving that the connections proposed preserve standard correctness notions such as non-interference.
Fichier principal
Vignette du fichier
478668_1_En_5_Chapter.pdf (350.49 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02313753 , version 1 (11-10-2019)

Licence

Paternité

Identifiants

Citer

Chandrika Bhardwaj, Sanjiva Prasad. Only Connect, Securely. 39th International Conference on Formal Techniques for Distributed Objects, Components, and Systems (FORTE), Jun 2019, Copenhagen, Denmark. pp.75-92, ⟨10.1007/978-3-030-21759-4_5⟩. ⟨hal-02313753⟩
39 Consultations
12 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More