Data-Dependent Confidentiality in DCR Graphs

Research output: Chapter in Book/Report/Conference proceedingArticle in proceedingsResearchpeer-review

Documents

  • Fulltext

    Final published version, 640 KB, PDF document

We present DCRSec, a confidentially aware declarative process language with data that employs data-dependent security levels and an information flow monitor that prevents the violation of information flow policies. Data-dependent security levels have been used to shape precise information flow policies and properly identify security compartments. We use an illustrative example to show that it also models process instances in a flexible but precise way. The semantics of the language is based on a version of the Dynamic Condition Response Graph language, which allows for declaring data-aware, event-based processes with finitary and infinitary computations subject to liveness properties and dynamically spawned sub-processes. The key technical contribution is to provide a termination-insensitive information flow monitor and prove non-interference, a soundness property, and transparency in all traces of DCRSec processes.

Original languageEnglish
Title of host publicationProceedings of the 25th International Symposium on Principles and Practice of Declarative Programming (PPDP 2023)
Number of pages13
PublisherAssociation for Computing Machinery
Publication date2023
Article number7
ISBN (Electronic)979-8-4007-0812-1
DOIs
Publication statusPublished - 2023
Event25th International Symposium on Principles and Practice of Declarative Programming, PPDP 2023 - As part of the ACM SIGPLAN conference on Systems, Programming, Languages, and Applications: Software for Humanity, SPLASH 2023, including LOPSTR 2023 - Lisbon, Portugal
Duration: 22 Oct 202323 Oct 2023

Conference

Conference25th International Symposium on Principles and Practice of Declarative Programming, PPDP 2023 - As part of the ACM SIGPLAN conference on Systems, Programming, Languages, and Applications: Software for Humanity, SPLASH 2023, including LOPSTR 2023
LandPortugal
ByLisbon
Periode22/10/202323/10/2023

Bibliographical note

Publisher Copyright:
© 2023 Owner/Author.

    Research areas

  • Business Processes, DCR Graphs, Information Flow Control, Privacy, Security Monitoring, Software Security

ID: 390399152