Modelling Downgrading in Information Flow Security

  • Authors:
  • Annalisa Bossi;Carla Piazza;Sabina Rossi

  • Affiliations:
  • Università Ca' Foscari di Venezia;Università Ca' Foscari di Venezia;Università Ca' Foscari di Venezia

  • Venue:
  • CSFW '04 Proceedings of the 17th IEEE workshop on Computer Security Foundations
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information flow security properties such as noninterferenceensure the protection of confidential data by stronglylimiting the flow of sensitive information. However, to dealwith real applications, it is often necessary to admit mechanismsfor downgrading or declassifying information.In this paper we propose a general unwinding frameworkfor formalizing different noninterference properties permittingdowngrading, i.e., allowing information to flow froma higher to a lower security level through a downgrader.The framework is parametric with respect to the observationequivalence used to discriminate between different processbehaviours. We prove general compositionality propertiesand provide conditions under which both horizontaland vertical refinements are preserved under all the securityproperties obtained as instances of the unwinding framework.Finally, we present a decision procedure to check oursecurity properties and prove some complexity results.