Abstract
In today's systems, restricting the authority of untrusted code is difficult because, by default, code has the same authority as the user running it. Object capabilities are a promising way to implement the principle of least authority, but being too low-level and fine-grained, take away many conveniences provided by module systems. We present a module system design that is capability-safe, yet preserves most of the convenience of conventional module systems. We demonstrate how to ensure key security and privacy properties of a program as a mode of use of our module system. Our authority safety result formally captures the role of mutable state in capability-based systems and uses a novel non-transitive notion of authority, which allows us to reason about authority restriction: the encapsulation of a stronger capability inside a weaker one.
| Original language | English |
|---|---|
| Title of host publication | HotSos '16: Proceedings of the Symposium and Bootcamp on the Science of Security |
| Publisher | Association for Computing Machinery (ACM) |
| Pages | 68-68 |
| ISBN (Print) | 978-1-4503-4277-3 |
| DOIs | |
| Publication status | Published - 2016 |
| Externally published | Yes |
Fingerprint
Dive into the research topics of 'Modules in wyvern: advanced control over security and privacy'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver