Synthesis from hyperproperties

被引:0
作者
Bernd Finkbeiner
Christopher Hahn
Philip Lukert
Marvin Stenger
Leander Tentrup
机构
[1] Saarland University,Reactive Systems Group
来源
Acta Informatica | 2020年 / 57卷
关键词
D O I
暂无
中图分类号
学科分类号
摘要
We study the reactive synthesis problem for hyperproperties given as formulas of the temporal logic HyperLTL. Hyperproperties generalize trace properties, i.e., sets of traces, to sets of sets of traces. Typical examples are information-flow policies like noninterference, which stipulate that no sensitive data must leak into the public domain. Such properties cannot be expressed in standard linear or branching-time temporal logics like LTL, CTL, or CTL∗\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\hbox {CTL}^*$$\end{document}. Furthermore, HyperLTL subsumes many classical extensions of the LTL realizability problem, including realizability under incomplete information, distributed synthesis, and fault-tolerant synthesis. We show that, while the synthesis problem is undecidable for full HyperLTL, it remains decidable for the ∃∗\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\exists ^*$$\end{document}, ∃∗∀1\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\exists ^*\forall ^1$$\end{document}, and the linear∀∗\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$${{ linear }}\;\forall ^*$$\end{document} fragments. Beyond these fragments, the synthesis problem immediately becomes undecidable. For universal HyperLTL, we present a semi-decision procedure that constructs implementations and counterexamples up to a given bound. We report encouraging experimental results obtained with a prototype implementation on example specifications with hyperproperties like symmetric responses, secrecy, and information flow.
引用
收藏
页码:137 / 163
页数:26
相关论文
共 25 条
[1]  
Brett N(2017)Rewriting-based runtime verification for alternation-free hyperltl Proce. TACAS. LNCS 10206 77-93
[2]  
Siddique U(1985)Security without identification: transaction systems to make big brother obsolete Commun. ACM 28 1030-1044
[3]  
Bonakdarpour B(2005)Quantified interference for a while language Electron. Notes Theor. Comput. Sci. 112 149-166
[4]  
Chaum D(2010)Hyperproperties J. Comput. Secur. 18 1157-1210
[5]  
Clark D(2017)Encodings of bounded synthesis Proc. TACAS. LNCS 10205 354-370
[6]  
Hunt S(2019)Monitoring hyperproperties Formal Methods Syst. Des. 15 519-539
[7]  
Malacaria P(2013)Bounded synthesis STTT 1 37-58
[8]  
Clarkson MR(2015)Detecting unrealizability of distributed fault-tolerant systems Log. Methods Comput. Sci. 52 264-268
[9]  
Schneider FB(1992)Proving noninterference and functional correctness using traces J. Comput. Secur. 32 733-749
[10]  
Faymonville P(1946)A variant of a recursively unsolvable problem Bull. Am. Math. Soc. undefined undefined-undefined