Sound Enforcement of Dynamic Release Information Flow Policy
Jeffrey Ching, Danfeng Zhang
摘要
Information flow analysis is the de facto method of assessing confidentiality and integrity issues. However, the widespread adoption of information flow analysis in real-world systems is still lacking, partly due to a fundamental gap between theory and practice: the dynamic nature of security concerns in real-world systems goes beyond the scope of existing techniques that assume a static policy (i.e., data secrecy does not change).
Recognizing the fundamental gap, a substantial amount of research has studied various aspects of it (e.g., enabling declassification, endorsement, and revocation policies). A recent work takes a step further by formalizing a promising end-to-end policy called dynamic release that unifies prior formalizations by allowing information flow restrictions to downgrade and upgrade in arbitrary ways. However, how to soundly enforce the powerful dynamic release policy is still an open question.
In this paper, we present the first type system that enforces dynamic release policy and formally prove its soundness. More specifically, we (1) formalize a core language that enables dynamic release policy, (2) develop a type system that checks dynamic release policy, (3) develop new proof techniques and formally prove that the type system enforces dynamic release policy, and (4) implement a prototype of the type system as an extension to the Rust language, along with case studies on a conference reviewing system and Civitas.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Compositional Security for Reentrant ApplicationsEthan Cecchetti, Siqiu Yao, Haobin Ni, Andrew C. MyersS&P 2021 · 被引用 42 次
- Mechanized logical relations for termination-insensitive noninterferenceSimon Oddershede Gregersen, Johan Bay, Amin Timany, Lars BirkedalPOPL 2021 · 被引用 14 次
- Cocoon: Static Information Flow Control in RustAda Lamba, Max Taylor, Vincent Beardsley, Jacob Bambeck 等OOPSLA 2024 · 被引用 9 次
- Cryptographically Secure Information Flow Control on Key-Value StoresLucas Waye, Pablo Buiras, Owen Arden, Alejandro Russo 等CCS 2017 · 被引用 8 次
- Carapace: Static-Dynamic Information Flow Control in RustVincent Beardsley, Chris Xiong, Ada Lamba, Michael D. BondOOPSLA 2025 · 被引用 3 次
相关 Paper
- Nonmalleable Information Flow ControlEthan Cecchetti, Andrew C. Myers, Owen ArdenCCS 2017 · 被引用 49 次
- Quest Complete: The Holy Grail of Gradual SecurityTianyu Chen, Jeremy G. SiekPLDI 2024 · 被引用 6 次
- Impossibility of Precise and Sound Termination-Sensitive Security EnforcementsMinh Ngo, Frank Piessens, Tamara RezkS&P 2018 · 被引用 5 次
- Verifiable Security Policies for Distributed SystemsFelix A. Wolf, Peter MüllerCCS 2024 · 被引用 1 次
- A Type System for Optimizing Dynamic IFCDaniel Galán Pascual, François Hublet, Srđan Krstić, Roman Fischer 等OOPSLA 2026
