Cornell University
Library
Cornell UniversityLibrary

eCommons

Help
Log In(current)
  1. Home
  2. Cornell University Graduate School
  3. Cornell Theses and Dissertations
  4. Semantics for Secure Software

Semantics for Secure Software

File(s)
Hirsch_cornellgrad_0058F_11681.pdf (1.03 MB)
focal.zip (34.29 KB)
flafol-coq.zip (155.98 KB)
Permanent Link(s)
https://doi.org/10.7298/6grg-xc95
https://hdl.handle.net/1813/67641
Collections
Cornell Theses and Dissertations
Author
Hirsch, Andrew Karl
Abstract

In order to build machine-checked proven-secure software, we need formal se curity policies that express what it means to be “secure.” We must then show that the semantics of our software matches the semantics of those policies. This requires formal semantics for both programs and policies. In this dissertation, we explore the semantics of effectful programs and the semantics of authorization policies. The most well-known class of effects are those that can be given semantics via a monad, though current research also focuses on those that can be given a semantics via a comonad. We compare three methods for combining these two popular options: one method requires extra semantic structure, whereas the other methods can be applied to any monadic and comonadic effects. If the extra semantic structure needed for the first method exists then the three semantics are equivalent. Otherwise, we show that the two remaining semantics correspond to strict and lazy interpretations of the effects. On the other side, we use authorization logics to express authorization policies. Authorization logics can be given semantics using either models or a proof system. We build a model theory for an authorization logic that more-closely expresses how authorization logics are used by systems than traditional models. We also build a proof system for an authorization logic that ensures that proofs of authorization respect information-security policies.

Description
Supplemental file(s) description: Coq Code for FOCAL, Coq code for FLAFOL
Date Issued
2019-08-30
Keywords
authorization
•
Logic
•
Comonad
•
Flow-Limited Authorization
•
Monad
•
Computer science
•
Programming Languages
Committee Chair
Tate, Ross Everett
Committee Member
Kozen, Dexter Campbell
Shore, Richard A.
Morrisett, John Gregory
Degree Discipline
Computer Science
Degree Name
Ph.D., Computer Science
Degree Level
Doctor of Philosophy
Rights
Attribution 4.0 International
Rights URI
https://creativecommons.org/licenses/by/4.0/
Type
dissertation or thesis

Site Statistics | Help

About eCommons | Policies | Terms of use | Contact Us

copyright © 2002-2026 Cornell University Library | Privacy | Web Accessibility Assistance