ridm@nrct.go.th   ระบบคลังข้อมูลงานวิจัยไทย   รายการโปรดที่คุณเลือกไว้

Restricting information flow in security APIs via typing

หน่วยงาน Edinburgh Research Archive, United Kingdom

รายละเอียด

ชื่อเรื่อง : Restricting information flow in security APIs via typing
นักวิจัย : Keighren, Gavin
คำค้น : security APIs , information flow , type system , non-interference
หน่วยงาน : Edinburgh Research Archive, United Kingdom
ผู้ร่วมงาน : Steel, Graham , Aspinall, David , Stark, Ian , Engineering and Physical Sciences Research Council (EPSRC)
ปีพิมพ์ : 2557
อ้างอิง : http://hdl.handle.net/1842/8963
ที่มา : -
ความเชี่ยวชาญ : -
ความสัมพันธ์ : V. Cortier, G. Keighren, and G. Steel. Automatic Analysis of the Security of XORBased Key Management Schemes. In O. Grumberg and M. Huth, editors, Proceedings of the 13th International Conference on Tools and Algorithms for Construction and Analysis of Systems (TACAS 2007), number 4424 in Lecture Notes in Computer Science, pages 538–552. Springer-Verlag, Mar. 2007. , G. Keighren. Model Checking Security APIs. Master’s thesis, School of Informatics, University of Edinburgh, Aug. 2006. Available online at http://www.inf.ed.ac. uk/publications/thesis/online/IM060368.pdf.
ขอบเขตของเนื้อหา : -
บทคัดย่อ/คำอธิบาย :

Security APIs are designed to enable the storage and processing of confidential data without that data becoming known to individuals who are not permitted to obtain it, and are central to the operation of Automated Teller Machines (ATM) networks, Electronic Point of Sale (EPOS) terminals, set-top boxes for subscription-based TV, pre-payment utility meters, and electronic ticketing for an increasing number of public transport systems (e.g., Oyster in London). However, since the early 2000s, it has become clear that many of the security APIs in widespread use contain subtle flaws which allow malicious individuals to subvert the security restrictions and obtain confidential data that should be protected. In this thesis, we attempt to address this problem by presenting a type system in which specific security properties are guaranteed to be enforced by security APIs that are well-typed. Since type-checking is a form of static analysis, it does not suffer from the scalability issues associated with approaches that simulate interactions between a security API and one or more malicious individuals. We also show how our type system can be used to model an existing security API and provide the same guarantees of security that the API authors proved it upholds. This result follows directly from producing a well-typed implementation of the API, and demonstrates how our type system provides security guarantees without requiring additional API-specific proofs.

บรรณานุกรม :
Keighren, Gavin . (2557). Restricting information flow in security APIs via typing.
    กรุงเทพมหานคร : Edinburgh Research Archive, United Kingdom .
Keighren, Gavin . 2557. "Restricting information flow in security APIs via typing".
    กรุงเทพมหานคร : Edinburgh Research Archive, United Kingdom .
Keighren, Gavin . "Restricting information flow in security APIs via typing."
    กรุงเทพมหานคร : Edinburgh Research Archive, United Kingdom , 2557. Print.
Keighren, Gavin . Restricting information flow in security APIs via typing. กรุงเทพมหานคร : Edinburgh Research Archive, United Kingdom ; 2557.