P. Samarati et al., INFORMATION-FLOW CONTROL IN OBJECT-ORIENTED SYSTEMS, IEEE transactions on knowledge and data engineering, 9(4), 1997, pp. 524-538
Citations number
17
Categorie Soggetti
Information Science & Library Science","Computer Sciences, Special Topics","Engineering, Eletrical & Electronic","Computer Science Artificial Intelligence","Computer Science Information Systems
In this paper, we describe a high assurance discretionary access contr
ol model for object-oriented systems. The model not only ensures prote
ction against Trojan horses leaking information, but provides the flex
ibility of discretionary access control at the same time. The basic id
ea of our approach is to check all information flows among objects in
the system in order to block possible illegal flows. An illegal flow a
rises when information is transmitted from one object to another objec
t in violation of the security policy. The interaction modes among obj
ects are taken into account in determining illegal flows. We consider
three different interaction modes that are standard interaction modes
found in the open distributed processing models. The paper presents fo
rmal definitions and proof of correctness of our flow control algorith
m.