Securing nonintrusive web encryption through information flow

  • Authors:
  • Lantian Zheng;Andrew C. Myers

  • Affiliations:
  • Google Inc., Mountain View, CA, USA;Cornell University, Ithaca, NY, USA

  • Venue:
  • Proceedings of the third ACM SIGPLAN workshop on Programming languages and analysis for security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes a nonintrusive encryption mechanism for protecting data confidentiality on the Web. The core idea is to encrypt confidential data before sending it to untrusted sites and use keystores on the Web to manage encryption keys without intervention from users. A formal language-based information flow model is used to prove the soundness of the mechanism.