SPLASH 2023
Sun 22 - Fri 27 October 2023 Cascais, Portugal
Sun 22 Oct 2023 16:30 - 17:00 at Oceanus - Session 4 Chair(s): Santiago Escobar

We present DCRSec, a confidentially aware declarative process language with data that employs data-dependent security levels and an information flow monitor that prevents the violation of information flow policies. Data-dependent security levels have been used to shape precise information flow policies and properly identify security compartments. We use an illustrative example to show that it also models process instances in a flexible but precise way. The semantics of the language is based on a version of the Dynamic Condition Response Graph language, which allows for declaring data-aware, event-based processes with finitary and infinitary computations subject to liveness properties and allowing dynamically spawned sub-processes. The key technical contribution is to provide a termination-insensitive information flow monitor and prove non-interference, a soundness property, and transparency in all traces of DCRSec processes.

Sun 22 Oct

Displayed time zone: Lisbon change

16:00 - 17:30
Session 4PPDP at Oceanus
Chair(s): Santiago Escobar
16:00
30m
Paper
Type-directed Program Transformation for Constant-Time Enforcement
PPDP
16:30
30m
Paper
Data-Dependent Confidentiality in DCR Graphs
PPDP
Eduardo Geraldo , João Costa Seco NOVA-LINCS; Nova University of Lisbon, Thomas T. Hildebrandt University of Copenhagen
17:00
30m
Break
---
PPDP