2005
DOI: 10.1007/11580850_14
|View full text |Cite
|
Sign up to set email alerts
|

A Practical Formal Model for Safety Analysis in Capability-Based Systems

Abstract: Abstract. We present a formal system that models programmable abstractions for access control. Composite abstractions and patterns of arbitrary complexity are modeled as a configuration of communicating subjects. The subjects in the model can express behavior that corresponds to how information and authority are propagated in capability systems. The formalism is designed to be useful for analyzing how information and authority are confined in arbitrary configurations, but it will also be useful in the reverse … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
9
0

Year Published

2005
2005
2016
2016

Publication Types

Select...
4
3
3

Relationship

1
9

Authors

Journals

citations
Cited by 13 publications
(9 citation statements)
references
References 16 publications
0
9
0
Order By: Relevance
“…The problem is that previous research (except Spiessens [10], [11], but see Section 7) focuses on reference graph dynamics. For a state in a program's execution, the reference graph is the graph with the allocated objects as nodes, and the references they hold to each other as edges.…”
Section: Introductionmentioning
confidence: 99%
“…The problem is that previous research (except Spiessens [10], [11], but see Section 7) focuses on reference graph dynamics. For a state in a program's execution, the reference graph is the graph with the allocated objects as nodes, and the references they hold to each other as edges.…”
Section: Introductionmentioning
confidence: 99%
“…They discuss examples when, using data diodes, capabilities can help guarantee the mandatory access-control discipline no write down in the Bell-LaPadula model. In a similar vein, Spiessens and Van Roy [45] spell out the examples from [35] in a more abstract setting.…”
Section: Related Workmentioning
confidence: 99%
“…The semantics of the underlying security model are encapsulated in a few simple rules. Hence, the model and its implementation lend themselves to formal analysis [27], which we believe will allow Annex to provide very strong security guarantees.…”
Section: The Annex Security Architecturementioning
confidence: 99%