Cryptographically Secure Information Flow Control on Key-Value Stores
Lucas Waye, Pablo Buiras, Owen Arden, Alejandro Russo, Stephen Chong
Abstract
We present Clio, an information flow control (IFC) system that transparently incorporates cryptography to enforce confidentiality and integrity policies on untrusted storage. Clio insulates developers from explicitly manipulating keys and cryptographic primitives by leveraging the policy language of the IFC system to automatically use the appropriate keys and correct cryptographic operations. We prove that Clio is secure with a novel proof technique that is based on a proof style from cryptography together with standard programming languages results. We present a prototype Clio implementation and a case study that demonstrates Clio's practicality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a83097bf-8531-4cf3-ad2f-548538d3569fCited by top-tier papers2
- Verifying Indistinguishability of Privacy-Preserving ProtocolsKirby Linvill, Gowtham Kaki, Eric WustrowOOPSLA 2023 · 2 citations
- Sound Enforcement of Dynamic Release Information Flow PolicyJeffrey Ching, Danfeng ZhangOOPSLA 2026
Related papers
- Viaduct: an extensible, optimizing compiler for secure distributed programsCosku Acay, Rolph Recto, Joshua Gancher, Andrew C. Myers et al.PLDI 2021 · 25 citations
- A Type System for Optimizing Dynamic IFCDaniel Galán Pascual, François Hublet, Srđan Krstić, Roman Fischer et al.OOPSLA 2026
- Co-Inflow: Coarse-grained Information Flow Control for Java-like LanguagesJian Xiang, Stephen ChongS&P 2021 · 12 citations
- Verifiable Security Policies for Distributed SystemsFelix A. Wolf, Peter MüllerCCS 2024 · 1 citation
- Cocoon: Static Information Flow Control in RustAda Lamba, Max Taylor, Vincent Beardsley, Jacob Bambeck et al.OOPSLA 2024 · 9 citations
