Secure Information Flow Connections
Chandrika Bhardwaj, Sanjiva Prasad

TL;DR
This paper introduces a mathematically rigorous framework based on Lagois connections for secure information flow between autonomous organizations with different security policies, ensuring security and flexibility.
Contribution
It extends Denning's lattice model to support inter-organizational information exchange using Lagois connections, maintaining security and autonomy.
Findings
Framework preserves non-interference security property
Supports modular and adaptable security policies
Extends to Decentralised Labels Model for bidirectional flows
Abstract
Denning's lattice model provided secure information flow analyses with an intuitive mathematical foundation: the lattice ordering determines permitted flows. We examine how this framework may be extended to support the flow of information between autonomous organisations, each employing possibly quite different security lattices and information flow policies. We propose a connection framework that permits different organisations to exchange information while maintaining both security of information flow as well as their autonomy in formulating and maintaining security policies. Our prescriptive framework is based on the rigorous mathematical framework of Lagois connections proposed by Melton, together with a simple operational model for transferring object data between domains. The merit of this formulation is that it is simple, minimal, adaptable and intuitive. We show that our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Security and Verification in Computing · Access Control and Trust
