Soft Constraints for Security

被引:2
作者
Bella, Giampaolo [1 ]
Bistarelli, Stefano [2 ,3 ]
Foley, Simon N. [4 ]
机构
[1] Univ Catania, Dipartimento Matemat & Informat, Catania, Italy
[2] Univ G DAnnunzio, Dipartimento Sci, Pescara, Italy
[3] CNR, Ist Informat & Telemat, Pisa, Italy
[4] Univ Coll Cork, Dept Comp Sci, Cork, Ireland
关键词
Constraints; Security Protocols; Integrity Policy;
D O I
10.1016/j.entcs.2005.07.011
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Integrity policies and cryptographic protocols have much in common. They allow for a number of participating principals, and consist of sets of rules controlling the actions that principals should or should not perform. They are intended to uphold various security properties, the crucial ones being integrity, confidentiality and authentication. This paper takes a unified view to the analysis of integrity policies and cryptographic protocols: they are artifacts that must be designed to be sufficiently robust to attack given an understood threat model. For example, integrity policy rules provide resilience to the threat of internal fraud, while cryptographic protocols provide resilience to the threat of replay and related attacks. The framework is modelled using (soft) constraints and analysis corresponds to the soft constraint satisfaction problem. Soft constraints facilitate a quantitative approach to analyzing integrity, confidentiality and authentication. Examples will be given: an integrity policy may achieve different levels of integrity under different circumstances; a protocol message may enjoy different levels of confidentiality for different principals; a principal can achieve different levels of authentication with different principals.
引用
收藏
页码:11 / 29
页数:19
相关论文
共 20 条
[1]  
[Accounting and Information Management Division United States General Accounting Office], 1996, GAOAFMD12195A
[2]  
BELLA G, 2004, THEOR PRACT LOG PROG, V4, P1
[3]   Semiring-based constraint satisfaction and optimization [J].
Bistarelli, S ;
Montanari, U ;
Rossi, F .
JOURNAL OF THE ACM, 1997, 44 (02) :201-236
[4]   Analysis of integrity policies using soft constraints [J].
Bistarelli, S ;
Foley, SN .
IEEE 4TH INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2003, :77-80
[5]  
Bistarelli S, 2002, LECT NOTES COMPUT SC, V2305, P53
[6]  
Bistarelli S., 2003, LNCS, V2788, P77
[7]  
Bistarelli S., 2002, LNCS
[8]  
Bistarelli S., 1995, P 14 INT JOINT C ART
[9]  
Bistarelli S., 2004, LNCS, V2962
[10]  
BISTARELLI S, 1999, CONSTRAINTS INT J, V4