Secure Programming using a Functional Paradigm
Jay-Evan J. Tevis · 2006
This paper investigates the advantages of the functional language paradigm and its use in secure programming. The intended audience is software professionals from either the computer security domain or the functional language domain who have not yet considered cross-domain synthesis of ideas. Secure programming describes those practices that software developers use to provide security features in their applications. To study its relationship to software development, secure programming can be divided into the following categories: safe program initialization, access control, input validation, cryptography, safe networking, safe random number generation, and anti-tampering. Software in these categories has historically been coded in imperative languages. More recently, object-oriented languages such as Java have also been used. What about a functional language such as Haskell? Does this language offer something new to secure programming? This paper provides an answer to that question. It lists features in Haskell that provide security benefits, identifies how Haskell is already serving the needs of some of the secure programming practices, and demonstrates how the CAST-128 encryption algorithm can be implemented successfully and efficiently in Haskell when the code is compiled rather than interpreted. The paper also compares the Haskell execution results to a similar implementation in C.