Secure program partitioning

S Zdancewic, L Zheng, N Nystrom… - ACM Transactions on …, 2002 - dl.acm.org
ACM Transactions on Computer Systems (TOCS), 2002dl.acm.org
This paper presents secure program partitioning, a language-based technique for protecting
confidential data during computation in distributed systems containing mutually untrusted
hosts. Confidentiality and integrity policies can be expressed by annotating programs with
security types that constrain information flow; these programs can then be partitioned
automatically to run securely on heterogeneously trusted hosts. The resulting
communicating subprograms collectively implement the original program, yet the system as …
This paper presents secure program partitioning, a language-based technique for protecting confidential data during computation in distributed systems containing mutually untrusted hosts. Confidentiality and integrity policies can be expressed by annotating programs with security types that constrain information flow; these programs can then be partitioned automatically to run securely on heterogeneously trusted hosts. The resulting communicating subprograms collectively implement the original program, yet the system as a whole satisfies the security requirements of participating principals without requiring a universally trusted host machine. The experience in applying this methodology and the performance of the resulting distributed code suggest that this is a promising way to obtain secure distributed computation.
ACM Digital Library