Computer Science ›› 2018, Vol. 45 ›› Issue (6A): 36-40.

Review of Trust Declassification for Software System

ZHU Hao1,2,CHEN Jian-ping1   

  1. School of Computer Science and Technology,Nantong University,Nantong,Jiangsu 226019,China1
    School of Computer Science and Technology,Nanjing University of Aeronautics and Astronautics,Nanjing 210016,China2
  • Online:2018-06-20 Published:2018-08-03

Abstract: Non-interference model is the baseline security model of information flow control.It ensures zero leakage of secret information,but its restrictiveness of security condition is too strong.Software system inevitably violates non-interference model and releases proper information for its requirement of function.In order to prevent attacker obtain extra information from the channel of information release,the channel should be under control and trusted declassification policy and enforcement mechanisms should be established.Existing declassification policies are classified into WHAT,WHO,WHERE and WHEN dimensions,and existing enforcement mechanisms are classified into static enforcement,dynamic enforcement and secure multi-execution.The characteristics and deficiencies of these mechanisms were compared,the challenge of following study was discussed,and the direction of future study was out-looked.

Key words: Confidentiality, Information flow control, Non-interference, Trusted declassification

CLC Number: 

  • TP311
