Nonmalleable Information Flow Control
Ethan Cecchetti, Andrew C. Myers, Owen Arden
Abstract
Noninterference is a popular semantic security condition because it offers strong end-to-end guarantees, it is inherently compositional, and it can be enforced using a simple security type system. Unfortunately, it is too restrictive for real systems. Mechanisms for downgrading information are needed to capture real-world security requirements, but downgrading eliminates the strong compositional security guarantees of noninterference. We introduce nonmalleable information flow, a new formal security condition that generalizes noninterference to permit controlled downgrading of both confidentiality and integrity. While previous work on robust declassification prevents adversaries from exploiting the downgrading of confidentiality, our key insight is transparent endorsement, a mechanism for downgrading integrity while defending against adversarial exploitation. Robust declassification appeared to break the duality of confidentiality and integrity by making confidentiality depend on integrity, but transparent endorsement makes integrity depend on confidentiality, restoring this duality. We show how to extend a security-typed programming language with transparent endorsement and prove that this static type system enforces nonmalleable information flow, a new security property that subsumes robust declassification and transparent endorsement. Finally, we describe an implementation of this type system in the context of Flame, a flow-limited authorization plugin for the Glasgow Haskell Compiler.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f175b69f-3979-4422-8ee6-2ec4c0034edeCited by top-tier papers9
- HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow SecurityAndrew Ferraiuolo, Mark Zhao, Andrew C. Myers, G. Edward SuhCCS 2018 · 63 citations
- Faceted Secure Multi ExecutionThomas Schmitz, Maximilian Algehed, Cormac Flanagan, Alejandro RussoCCS 2018 · 20 citations
- Generalized Policy-Based Noninterference for Efficient Confidentiality-PreservationShamiek Mangipudi, Pavel Chuprikov, Patrick Eugster, Malte Viering et al.PLDI 2023 · 3 citations
- Non-interference Preserving Optimising CompilationJulian Rosemann, Sebastian Hack, Deepak GargOOPSLA 2025 · 1 citation
- Tainted Secure Multi-Execution to Restrict Attacker InfluenceMcKenna McCall, Abhishek Bichhawat, Limin JiaCCS 2023 · 1 citation
Related papers
- Sound Enforcement of Dynamic Release Information Flow PolicyJeffrey Ching, Danfeng ZhangOOPSLA 2026
- Quest Complete: The Holy Grail of Gradual SecurityTianyu Chen, Jeremy G. SiekPLDI 2024 · 6 citations
- Structural Information Flow: A Fresh Look at Types for Non-interferenceHemant Gouni, Frank Pfenning, Jonathan AldrichOOPSLA 2025 · 1 citation
- Compositional Security Definitions for Higher-Order Where DeclassificationJan Menz, Andrew K. Hirsch, Peixuan Li, Deepak GargOOPSLA 2023 · 3 citations
- The Downgrading Semantics of Memory SafetyRené Rydhof Hansen, Andreas Stenbæk Larsen, Aslan AskarovPLDI 2026
