Integrity Policies via a Library in Haskell

Albert Disertholf, Alejandro Russo · 2011

Protecting confidentiality of data has become increasingly important for computing systems. Information-flow techniques have been developed over the years to achieve that purpose, leading to special-purpose languages that guarantee information-flow security in programs. However, rather than producing a new language from scratch, informationflow security can also be provided by a library. This paper proposes a library in Haskell that, besides confidentiality, considers another important aspect of security: integrity of data. Integrity of data seeks to prevent that programs destroy, accidentally or maliciously, information. We describe how to enforce different integrity policies by access control, data invariants, and information-flow integrity. To the best of our knowledge, a library that combines confidentiality and integrity policies has not been previously considered. Augmenting the set of enforceable policies develops further the changes for the library to be attractive for programmers. To evaluate our ideas, we implement an administrator of passwords that involves confidentiality and integrity policies in an interesting manner.

Read the paper · More papers on PaperTik