Skip to main content
QUICK REVIEW

[论文解读] Complexity and Unwinding for Intransitive Noninterference

Sebastian Eggert, Ron van der Meyden|arXiv (Cornell University)|Aug 6, 2013
Security and Verification in Computing参考文献 19被引用 6
一句话总结

本文確立了在有限狀態系統中驗證非傳遞非干擾安全策略的計算複雜度,證明P-security、IP-security和TA-security可透過新的有效且完備的解綁技術在多項式時間內判定,而TO-security與ITO-security則是不可判定的。本研究提供了針對不安全系統的高效演算法與反例生成機制。

ABSTRACT

The paper considers several definitions of information flow security for intransitive policies from the point of view of the complexity of verifying whether a finite-state system is secure. The results are as follows. Checking (i) P-security (Goguen and Meseguer), (ii) IP-security (Haigh and Young), and (iii) TA-security (van der Meyden) are all in PTIME, while checking TO-security (van der Meyden) is undecidable, as is checking ITO-security (van der Meyden). The most important ingredients in the proofs of the PTIME upper bounds are new characterizations of the respective security notions, which also lead to new unwinding proof techniques that are shown to be sound and complete for these notions of security, and enable the algorithms to return simple counter-examples demonstrating insecurity. Our results for IP-security improve a previous doubly exponential bound of Hadj-Alouane et al.

研究动机与目标

  • 確定在有限狀態系統中驗證非傳遞非干擾安全策略的計算複雜度。
  • 解決先前解綁技術在非傳遞策略下缺乏完備性的限制。
  • 提出IP-security與TA-security的新特徵描述與有效且完備的解綁關係。
  • 改進先前IP-security驗證的雙重指數時間複雜度界限。
  • 解決TO-security與ITO-security的可判定性問題,證明其在有限狀態系統中為不可判定。

提出的方法

  • 基於最大允許資訊流的作業模型,提出IP-security與TA-security的新特徵描述。
  • 提出針對IP-security與TA-security量身訂做的有效且完備的解綁關係,以支援自動化驗證。
  • 基於這些解綁關係開發演算法,使P-security、IP-security與TA-security的驗證可在多項式時間內執行。
  • 使用展開技術證明TA-security弱解綁的完備性,但此方法不保留雙邊等價性。
  • 應用一階可表達的解綁條件,以產生安全系統的判定程序。
  • 採用反例生成機制,以識別並調試不安全系統行為。

实验结果

研究问题

  • RQ1在具有非傳遞策略的有限狀態系統中,驗證P-security的計算複雜度為何?
  • RQ2能否為IP-security與TA-security發展出有效且完備的解綁技術,以實現高效驗證?
  • RQ3TO-security在有限狀態系統中是否可判定?其複雜度為何?
  • RQ4解綁方法能否調整以同時確保非傳遞非干擾策略的完備性與有效性?
  • RQ5新特徵描述與解綁技術如何改進先前IP-security的複雜度界限?

主要发现

  • P-security、IP-security與TA-security皆可在多項式時間內判定,改進了先前IP-security的雙重指數時間界限。
  • 針對IP-security與TA-security開發了新的有效且完備的解綁技術,支援高效自動化驗證。
  • 本文證明TO-security與ITO-security在有限狀態系統中為不可判定。
  • 基於展開的弱解綁對TA-security具有完備性,但不保留雙邊等價性,因而限制其在原系統中的適用性。
  • 所提出的演算法可在系統不安全時返回簡潔、人類可讀的反例,有助於系統改進。
  • 研究成果為狀態機模型與語言式安全策略的結合奠定了基礎,以支援更豐富的資料降級機制。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。