A method for ensuring the security of application information flow based on dependent permissions

By introducing a security guarantee method based on permissions in the application, combining permission checking and decryption policies, the problem of application information flow security is solved, and the security and integrity of information flow during the dissemination process is achieved.

CN115618331BActive Publication Date: 2025-06-10EAST CHINA NORMAL UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211154777.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-21
Publication Date
2025-06-10
Estimated Expiration
2042-09-21

AI Technical Summary

Technical Problem

It is difficult for the prior art to fully ensure the security of information flow in applications, especially during the information dissemination process, information with high security levels may be leaked to variables with low security levels.

Method used

A method for security guarantee of application information flow based on dependent permissions is proposed. By designing the language that includes permission checking syntax and function calls and the operation semantics of the dependent context permission set, combining permission access control and information flow security, a decryption policy is introduced to ensure the security of information flow during the propagation process.

Benefits of technology

It realizes security guarantee for application information flow, prevents high-security information from leaking to low-security levels, and improves the security and integrity of information flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115618331B_ABST
    Figure CN115618331B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for ensuring the security of application program information flow based on dependent permissions. The method combines permission dependence and information flow security, and introduces a decryption strategy, including the following steps: Step 1, build a scenario model for the security of application program information flow based on permission dependence; Step 2, combine the required syntactic elements according to the set scenario to construct a syntactic model; Step 3, propose operational semantics, define the system state according to the actual meaning of the program language during execution, and give the operational semantics of each syntactic element; Step 4, refer to the language system, establish an information flow security model, form an information flow security logic, and realize the security guarantee of the application program information flow. The present invention uses the method of permission checking to replace conditional statements, and solves the information flow security problem caused by different results of executing conditional branches. By using the decryption strategy, the function return value is always low, preventing the security risks that may be caused by high-security-level information as the return value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of software technology and information flow security technology, and relates to a method for ensuring the security of information flow in application programs based on dependent permissions. Specifically, it involves the content of permission access control. By designing a language that includes permission check syntax and function calls and the operational semantics of a set of dependent context permissions, a method for ensuring the security of information flow including permission access control is realized. Background Art

[0002] With the development of mobile technology, terminal devices such as smart mobile phones have made rapid progress and become an indispensable part of modern life. In smart phones, various types of terminal applications emerge in an endless stream, greatly enriching people's daily life and work. However, with the development and use of application programs, how to ensure the security of the information flow in application programs has become a hot issue that needs to be solved urgently.

[0003] Information flow security means that confidential information in an information processing system will not be obtained by an attacker through analyzing observable information during the end-to-end processing and transmission process. In other words, when different data and variables are marked with different security levels, information with a high security level will not be spread to a low security level. Nowadays, researchers in various countries have been committed to the research in the field of information flow security and have achieved remarkable results. In the past few decades, information flow security has been widely studied and applied in various fields, such as operating systems, Web services, blockchain, and cloud computing. Traditional research on information flow security focuses on whether the information flow is secure during the transmission process and does not pay attention to whether an application can obtain the information in the initial state. However, for application programs, the information that different application programs can access is different. If only the transfer of information flow is concerned, the entire process cannot be comprehensively described.

[0004] Access control refers to ensuring that information is not illegally used and accessed by restricting the ability and scope of accessing information. Simply put, access control can control the access of legitimate users within a legitimate range, prevent illegal access by illegal users, and also prevent unauthorized access by legitimate users. In order to achieve the confidentiality and integrity of information resources, all accesses of users to information in a system must be controlled by access control technology. However, access control technology can only control the security of information access at the source and cannot guarantee the security requirements of the authorized information during the transmission process. Summary of the Invention

[0005] To address the deficiencies of the prior art, the objective of the present invention is to provide a method for ensuring the security of the information flow of an application based on dependent permissions. The method is obtained by combining permission access control and information flow security after comprehensively considering the deficiencies of traditional information flow technologies applied to mobile programs based on the security requirements of the information flow of the application. A security policy that supports decryption is added to the method, making the inference more accurate.

[0006] The present invention proposes a security model for the information flow of an application based on dependent permissions, providing a feasible solution for the security of the information flow of the application. To achieve the above objective, a method for ensuring the security of the information flow of an application based on dependent permissions in the present invention combines permission dependence and information flow security and introduces a decryption policy, specifically including the following steps:

[0007] Step 1: Build a scenario model for the security of the information flow of an application based on permission dependence;

[0008] Step 2: Combine the required syntactic elements according to the set scenario to build a syntactic model;

[0009] Step 3: Propose operational semantics: Define the system state and give the operational semantics of each syntactic element according to the actual meaning of the program language during execution;

[0010] Step 4: Refer to the language system, establish an information flow security model, form an information flow security logic, and achieve the security guarantee of the information flow of the application.

[0011] The scenario model in Step 1 is built according to the security of the information flow on the mobile application. The scenario model, including the application, permissions, information, information flow code, etc., describes the entire process of an application accessing information from obtaining information access permissions to using information in subsequent information flows. The present invention focuses on this process described by the scenario model and develops a logical system to ensure the security of accessing information and using information.

[0012] The syntactic elements in the second step include expressions in different forms, statements of different types, and functions. The syntax model refers to a language system proposed based on the scenario model set in the first step and composed of syntactic elements according to syntactic rules, including the manifestation forms of expressions in the language, the types of statements supported in the language, and the formal definitions of functions in the language. In the present invention, two types of statements, namely, permission check statements and decryption assignment statements, are added on the basis of general programming languages. The permission check statements are used to check whether the user applying for access to information has the permissions required to access the information, so that users without certain information access permissions cannot access such information. The permission check statements are used to ensure the security of information access control. The decryption assignment statements are used when the user has information access permissions but the security level of the information being accessed is higher than the security level of the variable used to receive the resource. It reduces the security level of the high-security-level information and then performs the assignment operation, so that the information flow in the statement cannot be assigned from a high-security-level expression to a low-security-level variable. The decryption assignment statements are used to ensure the security of information flow.

[0013] The manifestation forms of expressions in the language represent four legal types of expressions in the language proposed by the present invention, including value type expressions, variable type expressions, binary operation expressions, and expression tuples;

[0014] The types of statements supported in the language represent all operation types that a program built according to this language can include, including null statements, ordinary assignment statements, sequential statements, conditional branch statements, loop statements, local variable definition statements, function call statements, decryption assignment statements, and permission check statements, etc.;

[0015] The present invention simply abstracts an application program into a set of functions, and each function is used to represent one or several functional points in the application program. When information interaction is required inside an application program or between two application programs, function calls or even nested function calls will be used to achieve it. The formal definition of functions in the language clearly gives the general form of functions in the present invention, and the general form is:

[0016]

[0017] where A.f represents the function named f in application program A, represents the input parameter, output represents the local variable, c is the function body of the function, output is the return value of the function, and {c; return output} is the scope of the local variable output.

[0018] The operational semantics of the third step include the semantics at the expression level (the operational semantics of expression types) and the semantics at the statement level (the operational semantics of statement types).

[0019] The semantics at the expression level includes three elements: system state, expression, and value type, expressing the value of the expression under a certain system state;

[0020] The system state is a binary tuple composed of memory and event trace;

[0021] The semantics at the expression level is determined by the syntax model, including:

[0022] 1. According to the syntax model, considering the assignment process of the expression, give the general form of the expression semantics;

[0023] 2. According to the general form of the expression semantics, give the semantics of each type of expression.

[0024] The semantics at the statement level includes five elements: application name, permission context, system state before execution, execution statement, and system state after execution, describing the change of the system state before and after executing a program statement in the current environment; the permission context refers to the set of permissions used for the current permission check;

[0025] The semantics at the statement level is determined by the syntax model, including:

[0026] 1. According to the syntax model, considering the execution process of the statement, give the general form of the statement semantics;

[0027] 2. According to the general form of the statement semantics, give the semantics of each statement.

[0028] In step four, the language system refers to the language system composed of the syntax model in step two and the operational semantics in step three.

[0029] The information flow security model in step four includes an access control model, an information flow model, an attacker model, and a decryption model. The present invention proposes a method that can ensure the information flow security for each operation that can write operational semantics.

[0030] The described access control model is determined according to access control technology and application actual needs, including:

[0031] 1. Introduce the concepts of atomic permissions and permission sets according to access control technology to build the access control model;

[0032] 2. Construct the mapping relationship between permissions and information to clarify how to use the access control mechanism to access information;

[0033] 3. According to the application actual needs, statically allocate a permission set to each application to perform access restrictions through the access control mechanism.

[0034] Specifically, the access control refers to introducing the concepts of atomic permissions and permission sets to control the secure access and reading of information. In the present invention, first, the correspondence between permissions and information is statically given, indicating that an application can access the information corresponding to a permission when it has the permission. Then, a permission set is statically set for each application to limit the scope of information that each application can access. Next, a permission context is defined to represent the permission set used for the current permission check. When each application executes a permission check statement, if the current permission context contains the permission being checked, the application can access the information corresponding to the checked permission; otherwise, it cannot access. The access control model can ensure that an application can only read legal information and guarantee that the information will not be illegally accessed.

[0035] The information flow model and the attacker model are determined according to information flow security technologies and actual application requirements, including:

[0036] 1. Introduce the concept of security levels for expressions according to information flow security technologies to build the access control model;

[0037] 2. Confirm the criteria for formulating the security levels of expressions and give how to determine the security levels of different types of expressions;

[0038] 3. Establish an attacker model and specify the scope of the attacker's permissions.

[0039] Specifically, the information flow model refers to defining the security level of each expression in the closed interval [low, high]. During the execution of an application, information flows through operations such as assignment statements. If the information does not flow from a high security level to a low security level during the flow process, it indicates that the information flow is secure; otherwise, the information flow is insecure. The information flow model can verify the legality of information usage after an application obtains information access permissions. If all operations in a code segment follow the information flow rules for transmission, the code segment meets information flow security. If there are operations in a code segment that do not follow the information flow rules for transmission and transmit information of a high security level to a low security level, then the information flow verification will not pass, indicating that there is information leakage during the information usage process.

[0040] The described attacker model is determined according to the information flow security technology and the actual needs of the application. It means that an attacker role is introduced into the system. The attacker can observe all variables and operations with security levels less than or equal to its own security level, but cannot see any variables and operations with security levels higher than its own security level. If the attacker cannot infer information with a security level higher than its own from observing different execution results of the program, then the program execution is secure; otherwise, it is insecure. For example, for the conditional statement if x := 0 then y = 0 else y = 2, assuming that the security level of variable x is higher than that of the attacker and the security level of variable y is lower than that of the attacker, then if the attacker sees the value of variable y after the execution condition, it can infer the value of the confidential information variable x, and at this time the information flow is insecure. To solve this problem, the present invention requires that the security levels of the conditions of conditional statements and loop statements be lower than that of the attacker. At this time, the attacker cannot infer information with a security level higher than its own from observing different execution results of the program.

[0041] The described decryption model is determined according to the decryption security policy and includes:

[0042] 1. Introduce the concept of decryption and define the decryption predicate; describe the meaning of the decryption predicate through actual scenarios;

[0043] 2. Give the establishment conditions of the decryption predicate according to the mapping relationship between permissions and information.

[0044] Specifically, the decryption model means that in order to ensure the secure execution of decryption assignment statements in the program, the system defines a decryption predicate to judge the security rationality of decryption operations. The decryption predicate includes five parameters: the security level of the expression before decryption, the security level of the expression after decryption, the system state, the decryption statement, and the application program. A decryption statement is secure if and only if the decryption predicate holds. The establishment of the decryption predicate depends on two conditions. First, the permission function of the expression to be decrypted in the decryption statement is defined; second, the set of permissions required for accessing the expression defined in the permission function should be a subset of the permission context P, and at this time the decryption predicate holds. The permission function described in the present invention classifies variables into two categories. One category is variables that require permissions to access, and the other category is variables that can be accessed without permissions. For variables that require permissions to access, the present invention defines a permission function to store the corresponding relationship between the accessed variables and the permissions required for access. This decryption model enriches the security policy and improves the accuracy of reasoning.

[0045] According to the access control model, attacker model, information flow model, and decryption model, determine the information flow security logic, including:

[0046] 1. Define the general judgment form for ensuring information flow security by the syntax of permission checking and the function call language;

[0047] 2. Give the logical rules that satisfy the language according to the general judgment form of information flow security.

[0048] The beneficial effects of the present invention include: The present invention proposes a method for ensuring the information flow security of application programs based on dependent permissions, including a set of formal languages for information flow security based on permissions and a set of logical rules supporting decryption strategies. By using permissions to control user access and using information flow models and attacker models to prevent information leakage during use and transmission. A program written according to the rules of the formal language in the invention is safe when each statement in the program satisfies the logical rules. Compared with traditional information flow, the present invention uses the method of permission checking instead of conditional statements to solve the information flow security problem caused by different execution conditional branch results. In addition, the present invention uses a decryption strategy, so that when the decryption predicate holds, the expression with a high security level can be downgraded in security level. This strategy avoids the transfer of high security level information to low security level information during information acquisition. At the same time, it also makes the function return value always low, preventing the security risks that may be caused by high security level information as the return value. Description of the Drawings

[0049] Figure 1 It is a flowchart of the method for ensuring the information flow security of application programs based on dependent permissions of the present invention.

[0050] Figure 2 It is a password verification example of traditional information flow.

[0051] Figure 3 It is a password verification example of the present invention.

[0052] Figure 4 It is a mobile banking login example of the present invention. Detailed Embodiments

[0053] Combined with the following specific embodiments and drawings, the present invention will be further described in detail. The processes, conditions, experimental methods, etc. for implementing the present invention, except for the specifically mentioned content below, are all common knowledge and well-known common sense in the art, and the present invention has no special limiting content.

[0054] The present invention discloses a method for ensuring the security of application program information flow based on dependent permissions, which relates to the information flow security direction in the field of software technology. In the implementation process of the present invention, a set of languages including permission check syntax and function calls, a set of semantics of dependent context permission sets, and a set of information flow security logics including access control are utilized. Among them, the language is a string language that implements function call functions. In the language, the present invention defines all syntax elements that can be included in program design, describes the types of expressions, the supported statement forms, and the formal definitions of functions. The present invention simply abstracts each application program into a set of functions, and the interaction between application programs is realized through function calls. Different from general string languages, the present invention introduces the concept of permissions, defines permission check statements, and sets decryption policies. The operational semantics uses the way of big-step semantics to describe the value-taking operations of each expression and the execution process of each statement in the language. The present invention uses application programs and context permission sets as the execution environment of the operational semantics to control the accessibility of expressions within and between applications. In order to implement the information flow security logic, the present invention establishes an attacker model to ensure that each logic is secure at the security level of the attacker. The present invention adds permission content to the traditional information flow, realizing the integration of permission access control and information flow security. In addition, a decryption security policy is added to the logic to make the reasoning more accurate.

[0055] The present invention proposes a method for ensuring the security of application program information flow based on dependent permissions, which mainly includes the following contents:

[0056] 1. Build a scenario model for the security of application program information flow based on permission dependence.

[0057] The application scenario of the present invention is set on mobile application programs. Each application program is abstracted into a set of functions, and the interaction within an application program and between two application programs is realized through function calls. Capital letters A, B,... are used to represent the names of application programs. The present invention introduces atomic permission p, which has a specific correspondence with variables in the system, that is, the permissions required to access each variable are set to control the access to variables. The finite set of permissions in the whole system is represented by P, that is, P = {p 1 , p 2 ,..., p n}, and the permission set of application program A is represented by the set P A . The permission set of each application program is a subset of the system permission set P, that is The present invention stipulates that the permission sets of all application programs are statically allocated in the initial state and cannot be dynamically modified later.

[0058] The present invention controls the access of an application program to information through the permission access mechanism of an access control model. If the set of permissions of the application program acting as the caller contains the permissions necessary for the information to be accessed, then the application program can access and use the information. Then, an information flow model and an attacker model are used to prevent security information leakage during the use and transmission of the application program after obtaining the information access permission.

[0059] 2. Construct a syntax model for the information flow security of application programs based on permission dependencies.

[0060] The present invention constructs a syntax model by combining the required syntax elements according to the set scenario; the syntax model is divided into the expression form in the language, the supported statement types in the language, and the formal definition of functions, which will be described one by one below:

[0061] 1) Syntax definition at the expression level

[0062]

[0063] · v represents an expression of value type, which is a specific number.

[0064] · x represents an expression of variable type and can be assigned a value.

[0065] · e op e represents a binary operation expression, where the op operation represents an arithmetic operation such as addition, subtraction, multiplication, etc. on two expressions, and e op e represents the resulting expression of performing the op operation on two expressions.

[0066] · represents a tuple expression, that is, is a tuple composed of expressions.

[0067] 2) Syntax definition at the statement level

[0068] c ::= skip | x := e | c 1 ; c 2 | if e then c 1 else c 2 | while e do c |

[0069] init x = e in c | x := callA.f(e) | x := ↓e | check(p) then c 1 else c 2

[0070] · skip is an empty statement and does not perform any operation.

[0071] ·x := e is an ordinary assignment statement, which simply assigns the value of expression e to variable x.

[0072] ·c 1 ; c 2 is a sequential statement, indicating the combined execution of statements c 1 and c 2 in combination.

[0073] ·if e then c 1 else c 2 is a conditional branch statement, indicating the execution of statement c when the conditional expression e is TRUE 1 and the execution of statement c when it is FALSE. 2 .

[0074] ·while e do c is a loop statement, indicating the execution of statement c when the conditional expression e is TRUE and exiting the loop when it is FALSE.

[0075] ·init x = e in c is a local variable definition statement, indicating the definition of local variable x with the scope of c.

[0076] ·x := call A.f(e) is a function call statement, indicating the call to function f of application A, where expression e is the passed parameter and the return value is stored in variable x.

[0077] ·x := ↓e is a decryption assignment statement, indicating first reducing the security level of expression e and then assigning the reduced value to variable x.

[0078] ·check(p)then c 1 else c 2 is a permission check statement, indicating checking whether permission p is in the context permission set. If it is, statement c 1 is executed; otherwise, statement c 2 is executed.

[0079] 3) Formal definition of function syntax

[0080]

[0081] Here, A.f represents the function of application A, and the function name is f. is the formal parameter of the function, whose type is a tuple of expressions, c is the execution statement of the function body, output is the local variable and also the return value of the function, and {c; return output} is the scope of the local variable output. Here, only the closed function is considered, that is, the variables appearing in statement c can only be the variables introduced in the parameter input or the local variables in the function.

[0082] 3. Semantic model of application information flow security based on permission dependence.

[0083] In the present invention, the system state μ is defined as a tuple (mem μ , tr μ ).

[0084] where mem μ is memory, which represents a set of values ​​assigned to all shared variables in the system state μ, and also represents a mapping relationship between a set of variables and values ​​in the system, that is, mem μ =[x 1 →v 1 , x 2 →v 2 , ..., x n →v n ], where x 1 , x 2 , ..., x n represents a finite set of all variables in the system, v 1 , v 2 , ..., v n Indicates the values ​​of all variables in the system, and uses mem μ (x 1 ) represents the variable x in the system state μ 1 The value of .

[0085] tr μ It is an event sequence, which represents the historical record of events experienced by the system when it runs from the initial state to the state μ. The present invention uses it to save all the assignment events contained in the system from the initial state to the current state, which is called a trace. Each element in the sequence is a finite set of events. In the present invention, events are composed of two types of events: first, ordinary assignment events ASG<lvl,x,e> , which means assigning the value of expression e to variable x with security level lvl. Second, decrypt the assignment statement DCF<lvl,x,e> , which means that the value of expression e is decrypted and assigned to variable x. After decryption, the security level of variable x is lvl.

[0086] The following is a brief introduction to the semantic design of the present invention. The semantic design is divided into two parts: expression semantics and statement semantics, namely the semantics at the expression level and the semantics of language statement execution mentioned above.

[0087] 1) Expression semantics

[0088] The expression semantics is in the form of indicating that the value of expression e in system state μ is v

[0089]

[0090]

[0091]

[0092]

[0093] · (Value) indicates that in system state μ, the value of numeric expression v is v.

[0094] · (Variable) indicates that in system state μ, the value of variable expression x is the value of variable x in memory in system state μ.

[0095] · (Tuple) indicates that in system state μ, when 1 ≤ i ≤ n, the value of expression e i is v i respectively, then the value of tuple expression is expressed as

[0096] · (BiOp) indicates that in system state μ, if the value of e 1 is v 1 , and the value of e 2 is v 2 , v 1 and v 2 are calculated through the binary operator to obtain the value v 3 , then in this state, the value obtained by e 1 and e 2 through the binary operator is v 3 .

[0097] 2) Statement semantics

[0098] The statement semantics is in the form of A, where A represents the application program, P represents the permission context, that is, the permission set for calling the application program A. <mem, tr> represents the system state. This judgment means that in the environment of application program A under permission context P, execute statement c. The system state before execution is <mem, tr>, and the system state after execution is <mem’, tr’>. If the statement is a statement block composed of multiple statements, then <mem″, tr″> is used to represent the final state of the execution of the statement block.

[0099]

[0100]

[0101]

[0102]

[0103]

[0104]

[0105]

[0106]

[0107]

[0108]

[0109]

[0110]

[0111]

[0112] · (Skip) represents executing a null statement, and the system state remains unchanged.

[0113] · (AssignN) represents an ordinary assignment statement. This statement assigns the value v of the expression e to the variable x. Additionally, an ordinary assignment event needs to be added to the event sequence. After execution, the value of the variable x in the memory of the system state is v.

[0114] · (Seq) represents a sequential statement. This statement means to execute c 1 ; c 2 The two statements, and the subsequent statement is executed in the environment after the previous statement is executed.

[0115] · (IfF) is a branch statement for the condition being FALSE. When the condition is FALSE, the statement c 2 is executed.

[0116] · (IfT) is a branch statement for the condition being TRUE. When the condition is TRUE, the statement c 1 is executed.

[0117] · (WhileF) is a loop statement for the condition being FALSE. When the condition is FALSE, the program does not execute the loop body, and the system state remains unchanged.

[0118] ·(WhileT) is a loop statement with the condition being TRUE. It keeps executing the loop body as long as the condition is TRUE and jumps out until the condition becomes FALSE.

[0119] ·(DefL) is a local variable definition statement. It defines the value of variable x as the value v of expression e, and the scope of variable x is c. After jumping out of the scope of the variable, the information of variable x needs to be deleted from the memory.

[0120] ·(AssignD) is a decryption assignment statement. This statement assigns the value v of expression e to variable x. Additionally, it needs to add the decryption assignment event to the event sequence. After execution, the value of variable x in the memory of the system state is v.

[0121] ·(CheckF) is a permission check statement with the condition being FALSE. When checking that permission p does not exist in the permission context P, statement c is executed. 2 Statement.

[0122] ·(CheckT) is a permission check statement with the condition being TRUE. When checking that permission p exists in the permission context P, statement c is executed. 1 Statement.

[0123] ·(Call) is a function call statement. This statement first needs to find the content of the called function in the system. Since application A calls the function of application B, the permission context is the permission set P of application A. A In this environment, the actual parameters are passed in to execute the function.

[0124] 4. Application program information flow security logic based on permission dependency

[0125] 1) Access control model

[0126] The present invention uses permissions for variable access control. The present invention divides variables into two categories. One category is variables that require permissions to access, and the other category is variables that can be accessed without permissions.

[0127] For variables that require permissions to access, the present invention uses the function Γ(x) to represent the permissions required to access variable x. For example, when Γ(x) = p, it means that permission p corresponds to the access of variable x. Then, when the permission context P contains permission p, the executing application can obtain the access right to variable x through check(p); otherwise, the application cannot access variable x. For variables that do not require permission to access, there is no need to control variable reading through permissions.

[0128] Therefore, in the case of no function call, application A can access all variables that do not require permission to access and its permission set P. AVariables corresponding to the permissions owned.

[0129] When a function call is made, if application A calls a function of application B, then the present invention will use the permission set of application A as the permission context for access control.

[0130] 2) Information flow model

[0131] The present invention defines the security level lvl of all expressions on the lattice of Low ≤ lvl ≤ High. First, define the security level for expression e. The present invention stipulates that an expression v of numerical type has no specific security level, and its security level depends on the security level of the variable it is assigned to. For a variable x with a defined permission function Γ(x), the present invention requires its security level to be the highest, High. For some variables, the present invention uses the function L(x) to define the security level and uses L(x) to represent the highest security level of the data held by variable x at any time. This means that in all assignments, the security level of variable x cannot exceed the upper limit L(x). For a variable x for which L(x) is not defined, the present invention defaults its security level to any level. When the present invention assigns the value of expression e to variable x through x := e, x automatically has the security level of expression e. The current security level of variable x depends on the security level of the last assigned expression. For a binary operation expression e := e 1 op e 2 , the security level of e is the higher one of the security levels of the two expressions involved in the operation. Similarly, in an expression tuple e = {e 1 , e 2 , e 3 ,..., e n}, the security level of expression e is the highest security level owned by all expressions in the tuple. In addition, the present invention uses lvl e to represent the current security level of expression e.

[0132] 3) Attacker model

[0133] The present invention introduces an attacker role to prove the security of the system. Here, it is assumed that the attacker is a passive attacker who can only obtain information by observing the execution of the program. Specifically, the present invention assumes that the attack level of the attacker is lvl a , then for all variables with a security level of lvl ≤ lvl a , the attacker can observe them. At the same time, if the assignment operation is a decryption assignment, variables with a security level of lvl ≤ lvl a after decryption can also be observed by the attacker.

[0134] The logic of the present invention is in the form of The judgment, where μ represents the current system state, A represents the name of the application program, P represents the permission context, and lvl a represents the security level of the attacker, and c represents the program statement. This judgment is true if and only if the system state is μ, the application program A is executed on the permission context P, and the program text c does not leak information to lvl a level.

[0135] 4) Decryption model

[0136] To make the decryption assignment statement execute securely, the present invention defines a decryption predicate:

[0137] D(lvl src , lvl des , μ, c, P)

[0138] In the definition of the predicate, lvl src represents the security level of the expression before decryption, lvl des represents the security level of the expression after decryption, μ represents the current system state, c represents the program statement, and P represents the permission context. For example, when the system state is μ, the decryption statement x := ↓e is executed on the permission context P. At this time, its decryption predicate is D(lvl e , L(x), μ, x := ↓e, P).

[0139] Whether the decryption predicate holds depends on the permission function Γ(e) of the decryption expression e. If the permission function Γ(e) of the expression e is defined, and then the decryption predicate holds, and at this time the decryption operation is secure. Otherwise, when the permission function Γ(e) of the expression e is not defined, or the permission function is defined, but when, the decryption predicate does not hold, and at this time the decryption operation is insecure.

[0140] Step four also involves an information flow security logic rule.

[0141] Specifically,

[0142] The information flow security logic rule of the application program based on dependent permissions is as follows:

[0143]

[0144]

[0145]

[0146]

[0147]

[0148]

[0149]

[0150]

[0151]

[0152]

[0153]

[0154]

[0155]

[0156]

[0157] · The (R-Skip) statement satisfies information flow security in any case because it does not perform any operations.

[0158] · (R-UAsgN) means that it is information flow secure when the L(x) function is not defined for variable x.

[0159] · (R-LAsgN) means that when the L(x) function is defined for variable x, it is information flow secure only if the security level of the current expression e is lower than L(x); otherwise, it is insecure.

[0160] · (R-Seq) means that when statement c is executed in system state μ 1 is secure, and after c 1 is executed, the system state transitions to μ', and when statement c 2 is executed in system state μ' and is also secure, then the sequential statement is information flow secure.

[0161] · (R-IfF) means that when the conditional expression e is FALSE, the entire statement is secure only if the security level of the conditional expression is lower than the attacker's security level and statement c 2 is executed in system state μ; otherwise, it is insecure.

[0162] · (R-IfT) means that when the conditional expression e is TRUE, the entire statement is secure only if the security level of the conditional expression is lower than the attacker's security level and statement c 1 is executed in system state μ; otherwise, it is insecure.

[0163] ·(R-WhileF) means that when the conditional expression e is FALSE, it is secure if it is guaranteed that the security level of the conditional expression is lower than that of the attacker; otherwise, it is insecure.

[0164] ·(R-WhileT) means that when the conditional expression e is TRUE, first, it is necessary to ensure that the security level of the conditional expression is lower than that of the attacker, and it is also necessary to ensure that the sequential statement c is secure when executed under the system state μ; if while e do c is secure, then the loop statement is secure; otherwise, it is insecure.

[0165] ·(R-DefL) means that if it is secure to execute the statement c after the value v of the expression e replaces the value of the variable x in memory, then the local variable definition is secure in terms of information flow; otherwise, it is insecure.

[0166] ·(R-AssignD) means that when the decryption predicate holds, the decryption assignment statement is secure; otherwise, the decryption statement is insecure.

[0167] ·(R-CheckF) means that when the permission p does not exist in the context permission set P, it is necessary to ensure that the statement c 2 is secure when executed in the current system state; otherwise, it is insecure.

[0168] ·(R-CheckT) means that when the permission p exists in the context permission set P, it is necessary to ensure that the statement c 1 is secure when executed in the current system state; otherwise, it is insecure.

[0169] (R-Call) means that first, find the function B.f. It is necessary to ensure that when the permission set of the calling application is used as the permission context, it is secure to execute the function body, and it is also necessary to ensure that the security level of the return value is not higher than that of the variable x that receives the return value; otherwise, the function call is not secure in terms of information flow.

[0170] The following uses two specific embodiments in actual scenarios to illustrate how to ensure information flow security by applying the method of the present invention:

[0171] Embodiment 1

[0172] 1. Password verification process

[0173] Figure 2 and Figure 3 The code shown simulates the password verification process. Figure 2 is the password verification process in traditional information flow security, Figure 3 and is the password verification process in the method proposed by the present invention.

[0174] In Figure 2Among them, the conditional statement represents a password verification process. When the condition is met, the user's information can be obtained. When the condition is not met, the user information cannot be obtained and is replaced with an empty string. Finally, the obtained information is returned as the function return value. Obviously, here the user information is confidential information corresponding to a high security level, and the empty string is a low security level. Since the traditional information flow requires that if the input changes, the attacker cannot observe the difference in the execution results. This requires that the two branches in the condition have the same security level. Here, if the security level of the variable information is high, there will be a great security risk when this variable is used as the function return value by other applications. On the contrary, if the security level of the variable information is low, then when the condition is met, there is an information leakage problem of assigning high security level information to a low security level variable. Therefore, the traditional information flow security method is not applicable to the information flow of application programs.

[0175] To solve this problem, the present invention makes two changes on the basis of the traditional information flow, as Figure 3 shown. First, a permission access control mechanism is introduced, and the permission check of the Check statement is used instead of the condition. In addition, a decryption policy is introduced to ensure that the return value of the function is of a low security level. This method not only solves the security of application resource acquisition but also ensures the security of the system information flow.

[0176] Embodiment 2

[0177] 2. Mobile banking login process

[0178] In life, mobile banking login requires two steps: mobile verification code authentication and authentication recognition. Figure 4 The code shown simulates the mobile banking login process, where p 1 represents whether the user has the permission to verify the mobile verification code, and the permission p represents the identity verification permission. Obviously, these two permissions are indispensable, otherwise the normal login will not be possible.

[0179] In this example, assume that the permission set P B of application B contains the permissions p and p 1 . Since the execution starts from application B, the permission context P at this time is P B . During the execution, first define a local variable y, and then execute the check(p 1 ) statement. Because the permission set of application B contains the permission p 1 , the then branch is executed to enter the function call statement. In the function call statement, the permission set P B of the caller application B should be used.As the permission context, it enters application A for execution. After defining the local variable x in A, it enters the check(p) statement. At this time, due to the permission set P B The function also contains permission p, so the decryption assignment statement is entered to lower the security level of the high-security user information to variable x, and then return it through the return value. After returning to application B, the variable y is used to receive the return value of the function call to obtain the final bank account information, and the login is successful.

[0180] In information flow security, the use of local variables needs to ensure that the information flow is safe within its scope, and function calls need to ensure that the information flow is safe within the function body. Therefore, if and only if the safety level of the function return value is less than or equal to L(y) and the classification predicate D(lvl information , L(x), μ, x: = ↓information, P) holds, the information flow is secure, otherwise it is unsafe.

[0181] The protection content of the present invention is not limited to the above embodiments. Without departing from the spirit and scope of the present invention, changes and advantages that can be thought of by those skilled in the art are included in the present invention and are protected by the attached claims.

Claims

1. A method for ensuring the security of the information flow of an application based on dependent permissions, characterized in that, the method combines permission dependence and information flow security, and introduces a decryption policy, including the following steps: Step 1: Build a scenario model for the security of the information flow of an application based on permission dependence; In Step 1, the scenario model is built according to the security of the information flow on the mobile application, and describes the whole process of an application accessing information from obtaining information access permission to using information in subsequent information flow, including the application, permission, information, and information flow code; Step 2: Combine the required syntactic elements according to the set scenario to build a syntactic model; Step 3: Propose operational semantics, define the system state according to the actual meaning of the program language during execution, and give the operational semantics of each syntactic element; In Step 2, the syntactic model is proposed according to the scenario model set in Step 1, adds permission check statements and decryption assignment statements on the basis of the program language, and is a language system composed of syntactic elements according to syntactic rules; the syntactic model includes the expression form of expressions in the language, the types of statements supported in the language, and the formal definition of functions in the language; The permission check statement is used to check whether the user applying for access to information has the permission required to access the information, so that users without a certain information access permission cannot access that kind of information, and the permission check statement is used to ensure the security of information access control; The decryption assignment statement is used when the user has the information access permission but the security level of the accessed information is higher than the security level of the variable used to receive the resource. It reduces the security level of the high-security-level information and then performs the assignment operation, so that the information flow in the statement cannot be assigned from a high-security-level expression to a low-security-level variable, and the decryption assignment statement is used to ensure the security of the information flow; Step 4: Refer to the language system, establish an information flow security model, form an information flow security logic, and realize the security guarantee of the information flow of the application; In Step 4, the language system refers to the language system composed of the syntactic model in Step 2 and the operational semantics in Step 3; The information flow security model includes an access control model, an information flow model, an attacker model, and a decryption model; The access control model is used to control the secure access and reading of information by introducing the concepts of atomic permissions and permission sets; The information flow model is used to define the security level of each expression in the closed interval [low, high], and the information flows through operations including assignment statements during the execution of the application; The attacker model means that an attacker role is introduced into the system. The attacker can observe all variables and operations with security levels less than or equal to its own security level, but cannot see any variables and operations with security levels higher than its own security level; The decryption model means that in order to ensure the secure execution of the decryption assignment statement in the program, the system defines a decryption predicate to judge the security rationality of the decryption operation.

2. The security guarantee method according to claim 1, characterized in that, The manifestation forms of expressions in the language include four legal types of expressions in the language, including value type expressions, variable type expressions, binary operation expressions, and expression tuples; The supported statement types in the language represent all operation types that a program built according to this language can include, including null statements, ordinary assignment statements, sequential statements, conditional branch statements, loop statements, local variable definition statements, function call statements, decryption assignment statements, and permission check statements; The formal definition of the function clearly gives the general form of the function, including the function name, formal parameters, local variables, function body, and return value. The general form is: Among them, A.f represents the function with the function name f in application A, represents the input parameter, output represents the local variable, c is the function body of the function, output is the return value of the function, and {c; return output} is the scope of the local variable output.

3. The security guarantee method according to claim 1, characterized in that, In step three, the operational semantics include semantics at the expression level and semantics at the statement level; The semantics at the expression level include three elements: system state, expression, and value type, expressing the value of the expression under a certain system state; The system state is a binary tuple composed of memory and event trace; The semantics at the statement level include five elements: application program name, permission context, system state before execution, execution statement, and system state after execution, describing the change of the system state before and after executing a program statement in the current environment; the permission context refers to the set of permissions used for the current permission check.

4. The security guarantee method according to claim 1, characterized in that, For the access control model, first statically give the correspondence between permissions and information, indicating that an application program can access the information corresponding to this permission when it has a permission, then statically set the permission set for each application program to limit the scope of information that each application program can access, and then define the permission context to represent the set of permissions used for the current permission check. When each application program executes a permission check statement, if the current permission context contains the permission being checked, the application program can access the information corresponding to the checked permission, otherwise it cannot.

5. The security guarantee method according to claim 1, characterized in that, For the information flow model, if the information does not flow from a high security level to a low security level during the flow process, it means that the information flow is secure, otherwise the information flow is insecure; after the application program obtains the information access permission, the information flow model detects whether all operations in the code segment follow the information flow rules for transmission to verify the legality of information use.

6. The security guarantee method according to claim 1, characterized in that, For the attacker model, if the attacker cannot infer information with a security level higher than that of the attacker by observing different execution results of the program, then the program execution is secure, otherwise it is insecure.

7. The security guarantee method according to claim 1, characterized in that, For the decryption model, the decryption predicate includes five parameters: the security level of the expression before decryption, the security level of the expression after decryption, the system state, the decryption statement, and the application program; when the permission function of the expression to be decrypted in the decryption statement is defined and the set of permissions required for accessing the decrypted expression defined in the permission function is a subset of the permission context P, the decryption predicate holds; the permission function is used to store the correspondence between the accessed variables and the permissions required for their access.