作者: Andrew C. Myers , Barbara Liskov
关键词: Data sharing 、 Declassification 、 Computer science 、 Distributed computing 、 Java 、 Language-based security 、 Static program analysis 、 Multilevel security 、 Confidentiality 、 Computer security 、 Security policy
摘要: Stronger protection is needed for the confidentiality and integrity of data, because programs containing untrusted code are rule rather than exception. Information flow control allows enforcement end-to-end security policies, but has been difficult to put into practice. This article describes decentralized label model, a new model information in systems with mutual distrust authority. The improves on existing multilevel models by allowing users declassify way, improving support fine-grained data sharing. It supports static program analysis flow, so that can be certified permit only acceptable flows, while largely avoiding overhead run-time checking. introduces language Jif, an extension Java provides checking using model.