Outline for January 8, 2007
-
Greetings and Felicitations!
-
Miscellaneous points
-
Copy flag and right
-
Own as a special right
-
Principle of attenuation of privilege
-
What is the safety question?
-
An unauthorized state is one in which a generic right r could be leaked into an entry in the ACM that did not previously contain r. An initial state is safe for r if it cannot lead to a state in which r could be leaked.
-
Question: in a given arbitrary protection system, is safety decidable?
-
Theorem: there is an algorithm that decides whether a given mono-operational system and initial state is safe for a given generic right.
-
General case: It is undecidable whether a given state of a given protection system is safe for a given generic right.
-
Represent TM as ACM
-
Reduce halting problem to it
-
Take-Grant
-
Counterpoint to HRU result
-
Symmetry of take and grant rights
-
Islands (maximal subject-only tg-connected subgraphs)
-
Bridges (as a combination of terminal and initial spans)
Here is a PDF version of this document.