Building systems that do not violate confidentiality of data through accidental information leakage is an increasingly important challenge. This is especially true for security-critical systems that handle sensitive information. A well-known obstacle for building secure systems is that security properties, such as confidentiality, are only addressed in late development phases. To combat this, information flow control by-construction (IFbC) was proposed. Similarly to correctness-by-construction for functional correctness, it aims at building systems such that they have a secure information flow by-construction. This paper presents an extension of that work in which we scale IFbC to the software architectural level for component-based systems. Our approach allows software architects to create a high-level design of the system using UML component models with explicit provided and required interfaces. We provide information flow specifications for the interfaces of components, which integrates the security concerns of the system in the design phase. We then demonstrate how the individual components can be realized according to information flow control by-construction, such that they adhere to their interface specifications. We provide rules for compatibility of interfaces and implementations that ensure confidential information flow, and prove that all component-based systems that can be constructed by our approach satisfy their security properties. In this way, we allow flexible architectural modeling of component-based systems combined with strong confidentiality guarantees from information flow control by-construction. Finally, we present the tool ArchFlow which assists developers with creating secure component-based systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Scaling Information Flow Control By-Construction to Component-Based Software Architectures

  • Rasmus C. Rønneberg,
  • Tabea Bordis,
  • Christopher Gerking,
  • Asmae Heydari Tabar,
  • Ina Schaefer

摘要

Building systems that do not violate confidentiality of data through accidental information leakage is an increasingly important challenge. This is especially true for security-critical systems that handle sensitive information. A well-known obstacle for building secure systems is that security properties, such as confidentiality, are only addressed in late development phases. To combat this, information flow control by-construction (IFbC) was proposed. Similarly to correctness-by-construction for functional correctness, it aims at building systems such that they have a secure information flow by-construction. This paper presents an extension of that work in which we scale IFbC to the software architectural level for component-based systems. Our approach allows software architects to create a high-level design of the system using UML component models with explicit provided and required interfaces. We provide information flow specifications for the interfaces of components, which integrates the security concerns of the system in the design phase. We then demonstrate how the individual components can be realized according to information flow control by-construction, such that they adhere to their interface specifications. We provide rules for compatibility of interfaces and implementations that ensure confidential information flow, and prove that all component-based systems that can be constructed by our approach satisfy their security properties. In this way, we allow flexible architectural modeling of component-based systems combined with strong confidentiality guarantees from information flow control by-construction. Finally, we present the tool ArchFlow which assists developers with creating secure component-based systems.