YIN Lihua, GUO Yunchuan, ZHANG Huibing, HUANG Wenting, FANG Binxing. Threat-Based Declassification and Endorsement for Mobile Computing[J]. Chinese Journal of Electronics, 2019, 28(5): 1041-1052. doi: 10.1049/cje.2019.06.007
Threat-Based Declassification and Endorsement for Mobile Computing

doi: 10.1049/cje.2019.06.007
Funds:  This work is supported by the National High Technology Research and Development Program (No.2015AA016007), National Natural Science Foundation of China (No.61672515, No.61662013), and Guangxi Natural Science Foundation (No.2017GXNSFAA198372)
  • Corresponding author: GUO Yunchuan (corresponding author) was born in 1977.He received the Ph.D.degree from the University of Chinese Academy of Sciences in 2011.He is an associate professor of the Institute of Information Engineering,CAS.His research interests include information security and formal verification.(Email:guoyunchuan@iie.ac.cn)
  • Received Date: 2017-11-22
  • Rev Recd Date: 2019-06-19
  • Publish Date: 2019-09-10
  • Declassification and endorsement can efficiently improve the usability of mobile applications. However, both declassify and endorse operations in practice are often ad-hoc and nondeterministic, thus, being insecure. From a new perspective of threat assessments, we propose the Threat-based typed security p-calculus (πTBTS) to model declassification and endorsement in mobile computing. Intuitively, when relaxing confidentiality policies and/or integrity policies, we respectively assess threats brought by performing these two relaxes. If these threats are acceptable, the declassification and/or endorsement operations are permitted; Otherwise, they are denied. The proposed assessments have explicit security conditions, results and less open parameters, so our approach solves the problem of the ad-hoc and nondeterministic semantics and builds a bridge between threat assessments and declassification/endorsement.
