WEBVTT

1
00:00:04.040 --> 00:00:06.429 A:middle L:90%
This is a talk that is you can tell from

2
00:00:06.429 --> 00:00:11.009 A:middle L:90%
the title is going to have some math and modeling

3
00:00:11.009 --> 00:00:13.759 A:middle L:90%
involved in it because it's talking about meta models.

4
00:00:14.339 --> 00:00:16.379 A:middle L:90%
Um but I will say more in a minute,

5
00:00:16.379 --> 00:00:19.109 A:middle L:90%
exactly what I'm hoping to convey and what I hope

6
00:00:19.109 --> 00:00:21.559 A:middle L:90%
you will get out of this talk. So here

7
00:00:21.559 --> 00:00:24.429 A:middle L:90%
is the obligatory kind of outline. First I wanted

8
00:00:24.429 --> 00:00:30.120 A:middle L:90%
to identify and make clear some ideas that are related

9
00:00:30.129 --> 00:00:35.210 A:middle L:90%
in general to information security and to talk about two

10
00:00:35.210 --> 00:00:38.179 A:middle L:90%
different approaches to that. And this is the one

11
00:00:38.179 --> 00:00:40.380 A:middle L:90%
this information flow control is the one that we're more

12
00:00:40.380 --> 00:00:43.460 A:middle L:90%
interested in in the research that we're doing. I

13
00:00:43.460 --> 00:00:45.640 A:middle L:90%
didn't want to introduce this idea about meta models and

14
00:00:45.640 --> 00:00:49.479 A:middle L:90%
talk about meta models for both of those forms of

15
00:00:49.490 --> 00:00:53.960 A:middle L:90%
confidentiality mechanisms, both for access control and for information

16
00:00:53.960 --> 00:00:59.640 A:middle L:90%
flow control. After we see those two meta models

17
00:00:59.649 --> 00:01:03.000 A:middle L:90%
make some observations and comparisons based on those meta models.

18
00:01:03.000 --> 00:01:04.640 A:middle L:90%
Talk about our future work and acknowledge some other

19
00:01:04.650 --> 00:01:08.569 A:middle L:90%
faculty that have been involved in this project. Now,

20
00:01:08.579 --> 00:01:11.379 A:middle L:90%
what are the expectations? As you'll see in

21
00:01:11.379 --> 00:01:14.319 A:middle L:90%
a minute? Because we're talking about meta models,

22
00:01:14.319 --> 00:01:17.590 A:middle L:90%
there's a lot of mathematical modeling in here using sort

23
00:01:17.590 --> 00:01:21.909 A:middle L:90%
of computational logic formalism. I'm not expecting you to

24
00:01:21.909 --> 00:01:23.799 A:middle L:90%
understand all of this. What I am trying to

25
00:01:23.799 --> 00:01:26.019 A:middle L:90%
accomplish what I'm trying to communicate and what I hope

26
00:01:26.019 --> 00:01:27.920 A:middle L:90%
you will take away from it is well, why

27
00:01:27.920 --> 00:01:30.170 A:middle L:90%
do we want to have such meta models to begin

28
00:01:30.170 --> 00:01:33.129 A:middle L:90%
with? What role do they play? What use

29
00:01:33.129 --> 00:01:36.540 A:middle L:90%
are they? And the short version of this talk

30
00:01:36.549 --> 00:01:40.719 A:middle L:90%
is there was another computer scientist who developed this meta

31
00:01:40.719 --> 00:01:45.370 A:middle L:90%
model framework for access control systems. And what we

32
00:01:45.370 --> 00:01:47.920 A:middle L:90%
are doing is building a parallel one for information flow

33
00:01:47.920 --> 00:01:51.170 A:middle L:90%
control systems. So that's the high level view of

34
00:01:51.170 --> 00:01:56.079 A:middle L:90%
what this work is all about. In presenting these two

35
00:01:56.079 --> 00:01:59.150 A:middle L:90%
models, I want to present them at a high

36
00:01:59.150 --> 00:02:01.730 A:middle L:90%
enough level that you could understand. Well what what's

37
00:02:01.730 --> 00:02:04.670 A:middle L:90%
the approach to building a model like this? What

38
00:02:04.670 --> 00:02:07.009 A:middle L:90%
does such a model look like? Um what are

39
00:02:07.009 --> 00:02:09.520 A:middle L:90%
some of its pieces? And how might I be

40
00:02:09.520 --> 00:02:13.909 A:middle L:90%
able to interpret some of those pieces? And how

41
00:02:13.909 --> 00:02:16.449 A:middle L:90%
in particular in this information flow model? How are

42
00:02:16.449 --> 00:02:20.439 A:middle L:90%
those parts organized? So it's gonna look very much

43
00:02:20.439 --> 00:02:23.889 A:middle L:90%
like something that's familiar to systems people if you think

44
00:02:23.889 --> 00:02:25.270 A:middle L:90%
about protocol stack, we're gonna show how all the

45
00:02:25.270 --> 00:02:29.979 A:middle L:90%
parts of this model are organized in some layered framework

46
00:02:29.990 --> 00:02:31.800 A:middle L:90%
so that you have some orientation in some sense about

47
00:02:31.810 --> 00:02:36.550 A:middle L:90%
what the model looks like. This part about comparison

48
00:02:36.550 --> 00:02:39.599 A:middle L:90%
and observations is giving some greater depth to the notion

49
00:02:39.599 --> 00:02:42.819 A:middle L:90%
of Ok, we built these things. So what

50
00:02:42.819 --> 00:02:43.900 A:middle L:90%
what are we going to do with them? How

51
00:02:43.900 --> 00:02:46.560 A:middle L:90%
do they help guide our thinking in some way.

52
00:02:46.639 --> 00:02:49.099 A:middle L:90%
Right, so that's the high level view of this

53
00:02:49.099 --> 00:02:51.159 A:middle L:90%
talk. I do want you if you have questions

54
00:02:51.159 --> 00:02:53.819 A:middle L:90%
during the talk to ask them because that will help

55
00:02:53.819 --> 00:02:57.629 A:middle L:90%
me why am I giving this talk? Because this

56
00:02:57.629 --> 00:03:00.180 A:middle L:90%
is my dry run for presenting the work that we've

57
00:03:00.180 --> 00:03:01.699 A:middle L:90%
been doing on this meta model at a conference later

58
00:03:01.699 --> 00:03:05.840 A:middle L:90%
this summer. So your questions are helping me to

59
00:03:05.840 --> 00:03:07.310 A:middle L:90%
sort of fine tune where the rough spots in this

60
00:03:07.319 --> 00:03:12.430 A:middle L:90%
talk are. Okay. So with that background and

61
00:03:12.430 --> 00:03:16.349 A:middle L:90%
with that introduction, let's get started. So what

62
00:03:16.349 --> 00:03:20.509 A:middle L:90%
is information security all about? And how does confidentiality

63
00:03:20.659 --> 00:03:24.240 A:middle L:90%
fit in here? So, information security has generally

64
00:03:24.240 --> 00:03:27.550 A:middle L:90%
talked about in terms of these three properties, the

65
00:03:27.550 --> 00:03:30.500 A:middle L:90%
C. I. A property's confidentiality, integrity and

66
00:03:30.500 --> 00:03:35.419 A:middle L:90%
accessibility. And each of these properties provides a different

67
00:03:35.430 --> 00:03:38.960 A:middle L:90%
sort of viewpoint on what security is all about.

68
00:03:38.639 --> 00:03:43.439 A:middle L:90%
So, for example, confidentiality is about ensuring that

69
00:03:43.439 --> 00:03:46.539 A:middle L:90%
only the right people see information okay, We don't

70
00:03:46.539 --> 00:03:49.550 A:middle L:90%
want information that's private to us being seen by people

71
00:03:49.550 --> 00:03:51.800 A:middle L:90%
that we don't know for example. So it's all

72
00:03:51.800 --> 00:03:53.060 A:middle L:90%
about who gets to see what and making sure that

73
00:03:53.060 --> 00:03:57.520 A:middle L:90%
only the right people see that information. So things

74
00:03:57.520 --> 00:04:01.439 A:middle L:90%
like identity theft are obviously attacks on confidentiality because you're

75
00:04:01.439 --> 00:04:03.840 A:middle L:90%
pretending to be someone and gaining access to something when

76
00:04:03.840 --> 00:04:05.870 A:middle L:90%
in fact you're not. And there are lots of

77
00:04:05.870 --> 00:04:11.960 A:middle L:90%
other attacks that you could pose integrity answers a different

78
00:04:11.960 --> 00:04:14.900 A:middle L:90%
question. It's let's make sure that the that the

79
00:04:14.900 --> 00:04:17.860 A:middle L:90%
information that people are seeing is the right information namely

80
00:04:17.860 --> 00:04:21.060 A:middle L:90%
that that information hasn't been corrupted by malicious parties.

81
00:04:21.939 --> 00:04:25.930 A:middle L:90%
So attacks on that are things like DNS attacks where

82
00:04:25.930 --> 00:04:28.350 A:middle L:90%
you think you're going to one website and a malicious

83
00:04:28.350 --> 00:04:31.120 A:middle L:90%
DNS servers actually routing your request to some other DNS

84
00:04:31.120 --> 00:04:34.470 A:middle L:90%
site. Alright. So that what you're seeing there

85
00:04:34.480 --> 00:04:38.920 A:middle L:90%
is not really the right information, it's posing as

86
00:04:38.930 --> 00:04:40.810 A:middle L:90%
the information that you want. But in fact it's

87
00:04:40.810 --> 00:04:44.949 A:middle L:90%
not correct availability means that even if we have the

88
00:04:44.949 --> 00:04:46.110 A:middle L:90%
right people and the right information, let's be sure

89
00:04:46.110 --> 00:04:49.189 A:middle L:90%
that that people can actually see the information when they

90
00:04:49.189 --> 00:04:53.000 A:middle L:90%
want to, that the information is accessible. So

91
00:04:53.000 --> 00:04:56.000 A:middle L:90%
denial of service attacks are a typical violation or a

92
00:04:56.000 --> 00:04:59.910 A:middle L:90%
typical way of attacking accessibility. What we're going to

93
00:04:59.910 --> 00:05:02.889 A:middle L:90%
focus on today is this question about confidentiality. How

94
00:05:02.889 --> 00:05:05.209 A:middle L:90%
do we ensure that only the right people see the

95
00:05:05.209 --> 00:05:11.949 A:middle L:90%
right information and there are two very high level frameworks

96
00:05:12.160 --> 00:05:16.610 A:middle L:90%
by which technical mechanisms have been organized in order to

97
00:05:16.620 --> 00:05:21.060 A:middle L:90%
provide confidentiality guarantees. one of them is access control

98
00:05:21.439 --> 00:05:26.740 A:middle L:90%
. And it answers the question about what information can

99
00:05:26.740 --> 00:05:29.750 A:middle L:90%
you access and how can you access that information.

100
00:05:29.759 --> 00:05:32.709 A:middle L:90%
And so it's usually framed in this way is a

101
00:05:32.709 --> 00:05:38.220 A:middle L:90%
particular principle principle being a person or an agent operating

102
00:05:38.220 --> 00:05:43.120 A:middle L:90%
on behalf of of some person is that principle allowed

103
00:05:43.120 --> 00:05:45.949 A:middle L:90%
to perform some action on some resource? That's the

104
00:05:45.949 --> 00:05:48.430 A:middle L:90%
way the question gets posed. And so the technical

105
00:05:48.430 --> 00:05:53.029 A:middle L:90%
mechanisms, I have to answer that question, given

106
00:05:53.029 --> 00:05:55.939 A:middle L:90%
an idea about a principle what the action is and

107
00:05:55.939 --> 00:05:58.050 A:middle L:90%
what the resources come back with a yes or no

108
00:05:58.050 --> 00:06:02.920 A:middle L:90%
answer. These access control mechanisms are all over the

109
00:06:02.920 --> 00:06:06.759 A:middle L:90%
place in our in the technical systems that we use

110
00:06:06.959 --> 00:06:12.089 A:middle L:90%
. So if you use um file systems on typical

111
00:06:12.089 --> 00:06:15.509 A:middle L:90%
Linux or other things, whether you do it through

112
00:06:15.509 --> 00:06:18.930 A:middle L:90%
the access permission bits and you're setting those for yourself

113
00:06:18.939 --> 00:06:23.019 A:middle L:90%
. World others in your group or you're using access

114
00:06:23.019 --> 00:06:26.639 A:middle L:90%
control lists on those file system mechanisms. Those are

115
00:06:26.639 --> 00:06:30.100 A:middle L:90%
all access control mechanism. If you don't have the

116
00:06:30.100 --> 00:06:31.259 A:middle L:90%
right settings, you can't get access to the information

117
00:06:32.139 --> 00:06:35.139 A:middle L:90%
. But if you have web page access you can

118
00:06:35.610 --> 00:06:40.819 A:middle L:90%
use various things that are interpreted by browsers to control

119
00:06:40.819 --> 00:06:43.660 A:middle L:90%
who can or cannot access a particular web page,

120
00:06:44.240 --> 00:06:47.829 A:middle L:90%
cryptographic based mechanisms. Our access control mechanisms, if

121
00:06:47.829 --> 00:06:49.779 A:middle L:90%
you have the key, you can access the information

122
00:06:49.779 --> 00:06:51.060 A:middle L:90%
. If you don't have the key you cannot.

123
00:06:51.839 --> 00:06:56.439 A:middle L:90%
So access control boils down to controlling that key and

124
00:06:56.439 --> 00:06:59.189 A:middle L:90%
who has access to that key. So if you

125
00:06:59.189 --> 00:07:02.860 A:middle L:90%
use things like https which has this transport layer um

126
00:07:03.439 --> 00:07:09.029 A:middle L:90%
service underneath. It's using a cryptographic method to control

127
00:07:09.029 --> 00:07:13.240 A:middle L:90%
access to the information. And In in all of

128
00:07:13.240 --> 00:07:16.040 A:middle L:90%
these cases there are many, many, many models

129
00:07:16.040 --> 00:07:18.670 A:middle L:90%
that have been developed over 30 or 40 years of

130
00:07:18.670 --> 00:07:23.220 A:middle L:90%
research. That's what all the faculty and graduate students

131
00:07:23.220 --> 00:07:25.959 A:middle L:90%
do. Alright, let's invent a new access control

132
00:07:25.959 --> 00:07:29.009 A:middle L:90%
model and our model will be different because it will

133
00:07:29.009 --> 00:07:30.990 A:middle L:90%
include some feature that nobody else has included before.

134
00:07:31.000 --> 00:07:34.660 A:middle L:90%
So you have models that have roles or context or

135
00:07:34.660 --> 00:07:40.160 A:middle L:90%
time or status or obligations or teams or promises or

136
00:07:40.160 --> 00:07:43.459 A:middle L:90%
hierarchies. You name it, you can probably find

137
00:07:43.459 --> 00:07:45.420 A:middle L:90%
a model out there that incorporates some or all of

138
00:07:45.420 --> 00:07:46.949 A:middle L:90%
those features. And if you want a new model

139
00:07:46.949 --> 00:07:47.459 A:middle L:90%
, just take any two of them that haven't been

140
00:07:47.459 --> 00:07:49.069 A:middle L:90%
combined yet and combine them together. And you have

141
00:07:49.069 --> 00:07:51.230 A:middle L:90%
a new model. So there are lots of those

142
00:07:51.230 --> 00:07:57.360 A:middle L:90%
kinds of models. Information flow control is a complementary

143
00:07:57.360 --> 00:08:01.569 A:middle L:90%
approach that really answers a very different question. It

144
00:08:01.569 --> 00:08:05.250 A:middle L:90%
says information that you're allowed to access. What are

145
00:08:05.250 --> 00:08:09.750 A:middle L:90%
you allowed to do with it? Okay. Because

146
00:08:09.750 --> 00:08:11.230 A:middle L:90%
the typical way to violate an access control mechanism is

147
00:08:11.230 --> 00:08:13.370 A:middle L:90%
you have an authorized user who gets the information and

148
00:08:13.370 --> 00:08:18.350 A:middle L:90%
gives it to somebody who's not authorized. And the

149
00:08:18.350 --> 00:08:20.750 A:middle L:90%
access control mechanism can't prevent that. And that's the

150
00:08:20.750 --> 00:08:26.389 A:middle L:90%
gap that information flow control tries to fill information that

151
00:08:26.389 --> 00:08:28.430 A:middle L:90%
you have. Where can it go? What can

152
00:08:28.430 --> 00:08:33.070 A:middle L:90%
you do with it? Ah So that's really about

153
00:08:33.070 --> 00:08:37.460 A:middle L:90%
looking at the flow of information, hence the name

154
00:08:37.529 --> 00:08:39.950 A:middle L:90%
from some source to some destination. So it is

155
00:08:39.950 --> 00:08:43.509 A:middle L:90%
very different orientation about the problem that it's trying to

156
00:08:43.509 --> 00:08:45.429 A:middle L:90%
solve. And as you can imagine that the mechanisms

157
00:08:45.429 --> 00:08:52.629 A:middle L:90%
that uh that are needed are considerably different. Okay

158
00:08:52.639 --> 00:08:56.129 A:middle L:90%
, well, um I told you that access control

159
00:08:56.129 --> 00:08:58.889 A:middle L:90%
mechanisms are all around and file systems, web pages

160
00:08:58.889 --> 00:09:03.409 A:middle L:90%
and so on. There are important places where systems

161
00:09:03.409 --> 00:09:05.759 A:middle L:90%
are trying to incorporate information flow controls as well.

162
00:09:07.240 --> 00:09:11.159 A:middle L:90%
So here's one a research system called High Star.

163
00:09:11.740 --> 00:09:15.039 A:middle L:90%
I wanted to approach the following problem. You all

164
00:09:15.039 --> 00:09:20.080 A:middle L:90%
have antivirus um software running on your machine. Your

165
00:09:20.080 --> 00:09:22.110 A:middle L:90%
antivirus software needs to be able to access every file

166
00:09:22.110 --> 00:09:26.620 A:middle L:90%
on your machine And it has to have access to

167
00:09:26.620 --> 00:09:30.409 A:middle L:90%
the network because it has to get updates and it

168
00:09:30.409 --> 00:09:33.779 A:middle L:90%
may have to give reports about viruses that it's found

169
00:09:33.779 --> 00:09:37.080 A:middle L:90%
in your machine. So here you have a piece

170
00:09:37.080 --> 00:09:39.090 A:middle L:90%
of software that has access to everything on your machine

171
00:09:39.090 --> 00:09:41.470 A:middle L:90%
and the network. How do you know that it's

172
00:09:41.470 --> 00:09:45.649 A:middle L:90%
not leaking everything on your machine out through the network

173
00:09:48.080 --> 00:09:50.340 A:middle L:90%
? And access control can't solve that problem because you

174
00:09:50.340 --> 00:09:52.740 A:middle L:90%
have to explicitly give it access to everything in your

175
00:09:52.740 --> 00:09:54.769 A:middle L:90%
machine and you have to give it access to the

176
00:09:54.769 --> 00:10:00.720 A:middle L:90%
network. And there have been cases about this like

177
00:10:00.720 --> 00:10:07.559 A:middle L:90%
this where free antivirus software has itself had deliberately um

178
00:10:07.570 --> 00:10:11.639 A:middle L:90%
malicious components embedded in it so that it could scan

179
00:10:11.639 --> 00:10:13.570 A:middle L:90%
systems, find things of interest and leak them out

180
00:10:13.570 --> 00:10:18.740 A:middle L:90%
through the network. A similar thing happens on smartphones

181
00:10:18.750 --> 00:10:22.259 A:middle L:90%
or handheld devices or tablets android devices in general.

182
00:10:22.259 --> 00:10:26.000 A:middle L:90%
So taint droid is a system that wants to help

183
00:10:26.000 --> 00:10:30.539 A:middle L:90%
you solve the problem of I've installed all these various

184
00:10:30.549 --> 00:10:33.909 A:middle L:90%
apps on my smartphone and some of them have access

185
00:10:33.909 --> 00:10:35.620 A:middle L:90%
to my address book. Some of them have access

186
00:10:35.620 --> 00:10:37.279 A:middle L:90%
to the network. Some of them have access to

187
00:10:37.279 --> 00:10:41.340 A:middle L:90%
my geolocation. How do I know the that these

188
00:10:41.340 --> 00:10:46.649 A:middle L:90%
apps aren't reporting this information to parties that I'm not

189
00:10:46.649 --> 00:10:50.230 A:middle L:90%
aware of. So taint droid looks at the flow

190
00:10:50.230 --> 00:10:54.990 A:middle L:90%
of information across apps to try and determine and provide

191
00:10:54.990 --> 00:11:01.059 A:middle L:90%
safeguards against the flow of information um that you deem

192
00:11:01.059 --> 00:11:05.679 A:middle L:90%
sensitive two apps that would leak it outside of your

193
00:11:05.690 --> 00:11:09.399 A:middle L:90%
control. So those are two examples of where information

194
00:11:09.399 --> 00:11:15.789 A:middle L:90%
flow control is really important. Yeah I said before

195
00:11:15.789 --> 00:11:20.129 A:middle L:90%
that that both of these forms of confidentiality control are

196
00:11:20.129 --> 00:11:24.269 A:middle L:90%
important. There's tons of access control models and there's

197
00:11:24.269 --> 00:11:28.860 A:middle L:90%
a wide variety of information flow control models as well

198
00:11:28.740 --> 00:11:37.110 A:middle L:90%
. So this um researcher from London steve barker responded

199
00:11:37.110 --> 00:11:39.759 A:middle L:90%
to a challenge that was raised in the technical community

200
00:11:41.740 --> 00:11:46.120 A:middle L:90%
um And he adopted the stance that that this is

201
00:11:46.120 --> 00:11:48.259 A:middle L:90%
a little quote from this paper that he wrote.

202
00:11:48.259 --> 00:11:52.070 A:middle L:90%
That's called the next 700 access control models or a

203
00:11:52.070 --> 00:11:56.559 A:middle L:90%
unifying meta model. And he takes the position that

204
00:11:56.840 --> 00:12:00.120 A:middle L:90%
What the research community should be doing at this point

205
00:12:00.120 --> 00:12:03.940 A:middle L:90%
is not populating 700 more access control models. Which

206
00:12:03.940 --> 00:12:05.799 A:middle L:90%
could easily be done just because we keep inventing new

207
00:12:05.799 --> 00:12:09.769 A:middle L:90%
factors or attributes that should be included in the model

208
00:12:09.769 --> 00:12:13.899 A:middle L:90%
or combining them in different ways. Because we really

209
00:12:13.899 --> 00:12:15.690 A:middle L:90%
don't know then if we have two models, how

210
00:12:15.690 --> 00:12:16.389 A:middle L:90%
are they different? How do they compare? Are

211
00:12:16.389 --> 00:12:18.629 A:middle L:90%
they is one really more powerful than the other.

212
00:12:18.700 --> 00:12:20.659 A:middle L:90%
So you've included this new feature, does that really

213
00:12:20.659 --> 00:12:26.350 A:middle L:90%
get you anywhere? How do you know? So

214
00:12:26.740 --> 00:12:31.649 A:middle L:90%
his notion was let's develop a meta model. Something

215
00:12:31.870 --> 00:12:35.259 A:middle L:90%
that is based on a few primitive notions that encapsulates

216
00:12:35.259 --> 00:12:39.600 A:middle L:90%
exactly what we mean by access control and such that

217
00:12:39.610 --> 00:12:41.960 A:middle L:90%
any particular model that you developed could then be obtained

218
00:12:41.960 --> 00:12:46.159 A:middle L:90%
by specializing the features of that meta model. So

219
00:12:46.159 --> 00:12:52.110 A:middle L:90%
then you can understand the comparison between specific models by

220
00:12:52.110 --> 00:12:56.779 A:middle L:90%
looking at whats the difference in their specializations. And

221
00:12:56.779 --> 00:12:58.870 A:middle L:90%
he called this paper in the next 700 access control

222
00:12:58.870 --> 00:13:01.519 A:middle L:90%
models because that's a reference to a paper from the

223
00:13:01.519 --> 00:13:05.919 A:middle L:90%
mid sixties that was facing the same issue at that

224
00:13:05.919 --> 00:13:07.899 A:middle L:90%
time. People were developing programming languages every week.

225
00:13:09.210 --> 00:13:11.240 A:middle L:90%
Every time you had a new application or a new

226
00:13:11.240 --> 00:13:13.960 A:middle L:90%
application domain, let's invent a new programming language with

227
00:13:13.340 --> 00:13:16.690 A:middle L:90%
features that are largely the same as other languages but

228
00:13:16.690 --> 00:13:20.600 A:middle L:90%
slightly different because our application domain has slightly different needs

229
00:13:22.240 --> 00:13:24.870 A:middle L:90%
. And at the time there was a computer scientist

230
00:13:24.870 --> 00:13:28.419 A:middle L:90%
Landon who wrote this paper about the next 700 programming

231
00:13:28.419 --> 00:13:31.600 A:middle L:90%
languages. Where he developed this philosophy about what we

232
00:13:31.600 --> 00:13:33.009 A:middle L:90%
should be doing is trying to look at the general

233
00:13:33.009 --> 00:13:37.970 A:middle L:90%
properties of programming languages and understand how these specific languages

234
00:13:37.980 --> 00:13:43.169 A:middle L:90%
fit into some bigger framework. So that's what barkers

235
00:13:43.120 --> 00:13:46.090 A:middle L:90%
set out to do. He set out to look

236
00:13:46.090 --> 00:13:48.690 A:middle L:90%
at all of these access control models and find out

237
00:13:48.690 --> 00:13:54.610 A:middle L:90%
whether a meta model could be developed. Something that

238
00:13:54.610 --> 00:13:58.620 A:middle L:90%
would encapsulate exactly and precisely all of the inherent critical

239
00:13:58.620 --> 00:14:03.490 A:middle L:90%
notions about what access control means. And this paper

240
00:14:03.490 --> 00:14:05.409 A:middle L:90%
was presented a few years ago at the sack matt

241
00:14:05.409 --> 00:14:07.620 A:middle L:90%
conference. And so it's appropriate that we're now trying

242
00:14:07.620 --> 00:14:13.289 A:middle L:90%
to bring the second piece to that um investigation by

243
00:14:13.289 --> 00:14:16.299 A:middle L:90%
looking at a similar question and developing a similar kind

244
00:14:16.299 --> 00:14:20.330 A:middle L:90%
of model for information flow control. So why would

245
00:14:20.330 --> 00:14:24.059 A:middle L:90%
you want this meta model? Well, first of

246
00:14:24.059 --> 00:14:28.000 A:middle L:90%
all, it's uh if nothing else, I mean

247
00:14:28.000 --> 00:14:28.750 A:middle L:90%
we're in an academic environment. What are we here

248
00:14:28.750 --> 00:14:31.539 A:middle L:90%
to do? We're here to learn about how things

249
00:14:31.539 --> 00:14:35.580 A:middle L:90%
work. And we're trying to understand what various aspects

250
00:14:35.580 --> 00:14:39.169 A:middle L:90%
of computing technology is all about. And so if

251
00:14:39.169 --> 00:14:41.279 A:middle L:90%
you could find this meta model, this meta model

252
00:14:41.279 --> 00:14:43.370 A:middle L:90%
would purport to be if you could find it a

253
00:14:43.370 --> 00:14:48.879 A:middle L:90%
distillation of the inherent features of access control. Right

254
00:14:48.879 --> 00:14:50.649 A:middle L:90%
? And that's useful to know because if you understand

255
00:14:50.649 --> 00:14:54.600 A:middle L:90%
that model, you understand all these 700 models you

256
00:14:54.600 --> 00:14:56.320 A:middle L:90%
don't understand the details but you understand the inherent basis

257
00:14:56.320 --> 00:15:01.600 A:middle L:90%
for them. So it provides a common basis for

258
00:15:01.610 --> 00:15:05.340 A:middle L:90%
uh specifying exactly what access control means. And for

259
00:15:05.340 --> 00:15:09.909 A:middle L:90%
understanding the relationship among different models, it could facilitate

260
00:15:09.909 --> 00:15:13.090 A:middle L:90%
sharing of access control policy information because if I have

261
00:15:13.090 --> 00:15:15.620 A:middle L:90%
this more general framework, if I have some policy

262
00:15:15.620 --> 00:15:18.179 A:middle L:90%
expressed in one model, I could look at what

263
00:15:18.190 --> 00:15:20.690 A:middle L:90%
that means in terms of the meta model framework and

264
00:15:20.690 --> 00:15:24.159 A:middle L:90%
then translated into the equivalent statement in some other model

265
00:15:24.539 --> 00:15:31.100 A:middle L:90%
. So there's ways of sharing policy constructs across models

266
00:15:31.110 --> 00:15:37.149 A:middle L:90%
or among applications. It's useful to policy administrators because

267
00:15:37.840 --> 00:15:39.669 A:middle L:90%
they don't have to start from the ground up.

268
00:15:39.679 --> 00:15:41.970 A:middle L:90%
And with the definition of a policy, All they

269
00:15:41.970 --> 00:15:43.179 A:middle L:90%
have to do is to say, well, I

270
00:15:43.179 --> 00:15:45.620 A:middle L:90%
have this piece of the meta model. I want

271
00:15:45.620 --> 00:15:48.059 A:middle L:90%
to specify my policy by specializing that in this way

272
00:15:48.639 --> 00:15:52.659 A:middle L:90%
and that's exactly what my policy is going to be

273
00:15:52.039 --> 00:15:54.750 A:middle L:90%
and it provides a rapid prototyping mechanism? You don't

274
00:15:54.750 --> 00:15:58.159 A:middle L:90%
have uh you don't necessarily have to worry about providing

275
00:15:58.159 --> 00:16:00.980 A:middle L:90%
the entire framework for the access control mechanism because that

276
00:16:00.980 --> 00:16:03.299 A:middle L:90%
might be built into whatever support you have for the

277
00:16:03.299 --> 00:16:07.799 A:middle L:90%
meta model. And then you could develop policy languages

278
00:16:08.440 --> 00:16:11.230 A:middle L:90%
. So there are lots of languages that people have

279
00:16:11.230 --> 00:16:15.019 A:middle L:90%
attempted to develop, but it's unclear in many cases

280
00:16:15.019 --> 00:16:18.460 A:middle L:90%
whether they have a precise semantics or not. So

281
00:16:18.460 --> 00:16:19.950 A:middle L:90%
it's possible now with this meta model to use that

282
00:16:19.950 --> 00:16:22.720 A:middle L:90%
as the basis for building a language. And if

283
00:16:22.720 --> 00:16:26.970 A:middle L:90%
the meta model is precisely specified in a mathematical way

284
00:16:26.970 --> 00:16:30.250 A:middle L:90%
, the language that is derived from that will have

285
00:16:30.259 --> 00:16:33.549 A:middle L:90%
a strong semantic basis as well. So there's lots

286
00:16:33.549 --> 00:16:37.789 A:middle L:90%
of valuable both sort of theoretical properties like these as

287
00:16:37.789 --> 00:16:42.559 A:middle L:90%
well as pragmatic properties like these for developing this notion

288
00:16:42.559 --> 00:16:45.919 A:middle L:90%
of a meta model. So what does it look

289
00:16:45.919 --> 00:16:52.320 A:middle L:90%
like? What kind of formalism could we resort to

290
00:16:52.940 --> 00:16:56.320 A:middle L:90%
in order to build a meta model for things like

291
00:16:56.320 --> 00:16:59.070 A:middle L:90%
access control. And so this is the approach that

292
00:16:59.080 --> 00:17:03.669 A:middle L:90%
that barker took, which is pretty straightforward. The

293
00:17:03.669 --> 00:17:04.759 A:middle L:90%
thing I want to convince you of is that you

294
00:17:04.759 --> 00:17:10.279 A:middle L:90%
could go read barker's paper and it would be entirely

295
00:17:10.279 --> 00:17:17.900 A:middle L:90%
sensible there. You you um you don't need to

296
00:17:17.910 --> 00:17:21.410 A:middle L:90%
um the mathematics that's used can be viewed in a

297
00:17:21.420 --> 00:17:23.829 A:middle L:90%
very approachable way. Maybe that's the best way to

298
00:17:23.839 --> 00:17:26.940 A:middle L:90%
frame this message. So what are the elements here

299
00:17:27.089 --> 00:17:30.329 A:middle L:90%
? They're just countable sets. How hard is the

300
00:17:30.329 --> 00:17:33.599 A:middle L:90%
set? Alright. Set notations are pretty straightforward,

301
00:17:33.599 --> 00:17:36.119 A:middle L:90%
so it's all based on having sets and what's in

302
00:17:36.119 --> 00:17:38.279 A:middle L:90%
the sets and what what can you infer about the

303
00:17:38.279 --> 00:17:41.970 A:middle L:90%
contents of these sets? So he defines a set

304
00:17:41.970 --> 00:17:45.579 A:middle L:90%
of things that he calls categories. And these categories

305
00:17:45.579 --> 00:17:48.160 A:middle L:90%
just represent elements that you're trying to model. So

306
00:17:48.160 --> 00:17:52.750 A:middle L:90%
there might be classes of users that all have a

307
00:17:52.750 --> 00:17:56.529 A:middle L:90%
similar kind of attributes or it might be all of

308
00:17:56.539 --> 00:18:00.700 A:middle L:90%
the um files that have a particular kind of security

309
00:18:00.700 --> 00:18:04.279 A:middle L:90%
clearance. So these categories are just ways of grouping

310
00:18:04.279 --> 00:18:07.490 A:middle L:90%
similar things together and what what's similar about them may

311
00:18:07.500 --> 00:18:12.440 A:middle L:90%
vary widely from one model to the other and you

312
00:18:12.440 --> 00:18:15.250 A:middle L:90%
need all of these things, we saw them earlier

313
00:18:15.250 --> 00:18:18.160 A:middle L:90%
because this is the foundation for the questions that need

314
00:18:18.160 --> 00:18:23.380 A:middle L:90%
to be answered. Can this principle undertake this action

315
00:18:23.390 --> 00:18:26.680 A:middle L:90%
on this resource? So we need to be able

316
00:18:26.680 --> 00:18:29.170 A:middle L:90%
to model those elements but that's all we need.

317
00:18:30.240 --> 00:18:30.809 A:middle L:90%
Now, I should say if you read barker's paper

318
00:18:30.809 --> 00:18:33.369 A:middle L:90%
there are some other things in there because he wants

319
00:18:33.369 --> 00:18:34.809 A:middle L:90%
to include other capabilities. So I'm trimming this down

320
00:18:34.809 --> 00:18:41.200 A:middle L:90%
just a little bit um but not much. Alright

321
00:18:41.200 --> 00:18:42.910 A:middle L:90%
, so that's what we have to work with and

322
00:18:42.910 --> 00:18:47.990 A:middle L:90%
how do we put this all together? So here

323
00:18:47.990 --> 00:18:52.769 A:middle L:90%
is what the core axiom in barker's model looks like

324
00:18:52.140 --> 00:19:00.789 A:middle L:90%
and his um contribution is that that core axiom says

325
00:19:00.789 --> 00:19:03.859 A:middle L:90%
exactly what access control is and every access control model

326
00:19:03.859 --> 00:19:08.460 A:middle L:90%
can be derived from this simply by specializing its operations

327
00:19:10.240 --> 00:19:11.750 A:middle L:90%
. Right. And that's pretty cool because it's one

328
00:19:11.750 --> 00:19:22.410 A:middle L:90%
line long. Ah here's the antivirus software leaking information

329
00:19:22.410 --> 00:19:26.859 A:middle L:90%
from my machine and interfering with the talk. So

330
00:19:26.859 --> 00:19:30.900 A:middle L:90%
what does this line mean? Well, first of

331
00:19:30.900 --> 00:19:32.859 A:middle L:90%
all, let's look at the graphical form because it's

332
00:19:32.859 --> 00:19:36.759 A:middle L:90%
easier to see. So what we need to do

333
00:19:36.759 --> 00:19:38.569 A:middle L:90%
is to figure out whether this is something that we

334
00:19:38.569 --> 00:19:41.950 A:middle L:90%
would allow. Can this principle perform that action on

335
00:19:41.950 --> 00:20:02.549 A:middle L:90%
a given resource and let me just kill this thing

336
00:20:06.740 --> 00:20:14.730 A:middle L:90%
. Thank you. Right. Alright. So we

337
00:20:14.730 --> 00:20:15.349 A:middle L:90%
want to know whether we should allow that or not

338
00:20:15.940 --> 00:20:21.180 A:middle L:90%
. And that triple of things that's called an authorization

339
00:20:21.579 --> 00:20:30.359 A:middle L:90%
that is Do we want to authorize this? Seriously

340
00:20:30.839 --> 00:20:37.769 A:middle L:90%
? I can't kill this thing. Come on.

341
00:20:45.339 --> 00:20:48.730 A:middle L:90%
And now I've lost my mouse too. There it

342
00:20:48.730 --> 00:21:02.579 A:middle L:90%
is. Go away. Okay. Let's hope that

343
00:21:02.579 --> 00:21:04.240 A:middle L:90%
holds for a while. So do we want to

344
00:21:04.240 --> 00:21:07.380 A:middle L:90%
allow that authorization or not? And the answer is

345
00:21:07.380 --> 00:21:11.400 A:middle L:90%
well, look to see if this principle is in

346
00:21:11.400 --> 00:21:15.130 A:middle L:90%
some category. And if you can find a subset

347
00:21:15.140 --> 00:21:21.529 A:middle L:90%
in that category which contains this pair which is referred

348
00:21:21.529 --> 00:21:23.390 A:middle L:90%
to as a permission. It's a binding of an

349
00:21:23.390 --> 00:21:26.490 A:middle L:90%
action and a resource together. If you can find

350
00:21:26.490 --> 00:21:30.750 A:middle L:90%
that permission in some subset, then you would allow

351
00:21:30.750 --> 00:21:36.529 A:middle L:90%
this authorization. Right? So the more linear way

352
00:21:36.529 --> 00:21:38.430 A:middle L:90%
of looking at that is And you can read this

353
00:21:38.430 --> 00:21:44.900 A:middle L:90%
perfectly well, as a prologue statement. Is is

354
00:21:44.900 --> 00:21:48.259 A:middle L:90%
this allowed. Is that true in our system?

355
00:21:48.839 --> 00:21:52.299 A:middle L:90%
It is provided we could find bindings that satisfy these

356
00:21:52.299 --> 00:21:57.690 A:middle L:90%
constraints. So if we can find that P is

357
00:21:57.690 --> 00:22:02.170 A:middle L:90%
a member of some category C. And that's what

358
00:22:02.170 --> 00:22:04.730 A:middle L:90%
this pc a relationship tells us whether P is in

359
00:22:04.730 --> 00:22:07.920 A:middle L:90%
some category. And if that category contains some other

360
00:22:07.920 --> 00:22:11.089 A:middle L:90%
category C. Prime. And if that category C

361
00:22:11.089 --> 00:22:17.109 A:middle L:90%
prime contains this pair, then this is true in

362
00:22:17.109 --> 00:22:22.150 A:middle L:90%
our system. And in this paper barker shows,

363
00:22:22.150 --> 00:22:25.170 A:middle L:90%
okay, you're familiar with this access model. Here's

364
00:22:25.170 --> 00:22:26.559 A:middle L:90%
how you specialize our operations in order to get it

365
00:22:27.039 --> 00:22:30.829 A:middle L:90%
. If you're familiar with some other access control model

366
00:22:30.829 --> 00:22:33.630 A:middle L:90%
, here's how you specify the operation. So just

367
00:22:33.640 --> 00:22:37.180 A:middle L:90%
to um so I'm not going to spend much time

368
00:22:37.180 --> 00:22:40.839 A:middle L:90%
on this. But just to give you a sense

369
00:22:40.839 --> 00:22:42.980 A:middle L:90%
that the mathematics is not particularly complicated, but it

370
00:22:42.980 --> 00:22:47.710 A:middle L:90%
is precise. Here's what this say this pc a

371
00:22:47.720 --> 00:22:49.569 A:middle L:90%
relationship is all about, right. This is a

372
00:22:49.569 --> 00:22:53.660 A:middle L:90%
relationship that says uh this pair. Some principle in

373
00:22:53.660 --> 00:22:59.450 A:middle L:90%
some category is in this relation. If and only

374
00:22:59.450 --> 00:23:02.559 A:middle L:90%
if that P happens to be assigned to this category

375
00:23:03.539 --> 00:23:03.829 A:middle L:90%
. Right. So this is just a way of

376
00:23:03.829 --> 00:23:08.420 A:middle L:90%
asking is pee in that category. Right. And

377
00:23:08.420 --> 00:23:11.990 A:middle L:90%
this is just a way of asking is this pair

378
00:23:12.099 --> 00:23:18.359 A:middle L:90%
in that category. So it's based on very simple

379
00:23:18.359 --> 00:23:22.859 A:middle L:90%
things. You have countable sets and you have relations

380
00:23:22.869 --> 00:23:26.700 A:middle L:90%
that talk about elements of those sets. And on

381
00:23:26.700 --> 00:23:30.410 A:middle L:90%
the basis of that you get this core axiom,

382
00:23:30.940 --> 00:23:33.680 A:middle L:90%
which is sort of the distillation of what access control

383
00:23:33.680 --> 00:23:34.970 A:middle L:90%
means. Now, can you do anything with that

384
00:23:34.970 --> 00:23:37.950 A:middle L:90%
? Well, here's a really trivial example, suppose

385
00:23:37.950 --> 00:23:41.750 A:middle L:90%
we have a system where we have three files,

386
00:23:41.750 --> 00:23:42.710 A:middle L:90%
A. B and C. We have three principles

387
00:23:42.710 --> 00:23:45.630 A:middle L:90%
. Alice, bob and craig. And we want

388
00:23:45.630 --> 00:23:48.640 A:middle L:90%
to express some access control relationships about which of those

389
00:23:48.640 --> 00:23:52.359 A:middle L:90%
files are accessible to those principles and in which ways

390
00:23:53.339 --> 00:23:56.519 A:middle L:90%
. So here it's done very generically. I didn't

391
00:23:56.529 --> 00:23:59.430 A:middle L:90%
actually have great names for these things. So we

392
00:23:59.430 --> 00:24:00.900 A:middle L:90%
make up several categories. So here are the categories

393
00:24:00.900 --> 00:24:03.869 A:middle L:90%
are C. Zero through C. Four. And

394
00:24:03.869 --> 00:24:07.839 A:middle L:90%
here's Alice, we put Alice in category C1.

395
00:24:07.140 --> 00:24:11.420 A:middle L:90%
So what is Alice able to do according to that

396
00:24:11.420 --> 00:24:12.069 A:middle L:90%
core axiom? What we have to be able to

397
00:24:12.069 --> 00:24:17.420 A:middle L:90%
find is some permission that is in C. One

398
00:24:17.420 --> 00:24:19.059 A:middle L:90%
or a subset of C. One. So here

399
00:24:19.059 --> 00:24:22.430 A:middle L:90%
we see that read A is a permission that is

400
00:24:22.430 --> 00:24:26.009 A:middle L:90%
in a category which is a subset of C.

401
00:24:26.009 --> 00:24:29.250 A:middle L:90%
One. So we could for example allow Alice to

402
00:24:29.250 --> 00:24:32.750 A:middle L:90%
read L. A. And in a similar way

403
00:24:32.750 --> 00:24:36.539 A:middle L:90%
Alice could read file be and could write to file

404
00:24:36.539 --> 00:24:40.089 A:middle L:90%
A. This writing to file A is allowed not

405
00:24:40.089 --> 00:24:42.450 A:middle L:90%
only to Alice, but it's also allowed to bob

406
00:24:42.839 --> 00:24:48.170 A:middle L:90%
because this permission is also in another category. Principles

407
00:24:48.170 --> 00:24:49.690 A:middle L:90%
and permissions can be in multiple categories all at the

408
00:24:49.690 --> 00:24:52.950 A:middle L:90%
same time because you might want to be able to

409
00:24:52.950 --> 00:24:57.180 A:middle L:90%
express different kinds of constraints. We see here,

410
00:24:57.180 --> 00:25:00.990 A:middle L:90%
for example that craig is able to read both of

411
00:25:00.990 --> 00:25:03.809 A:middle L:90%
the files that Alice can read A and B but

412
00:25:03.819 --> 00:25:08.539 A:middle L:90%
cannot write to A. Because we are not able

413
00:25:08.539 --> 00:25:14.049 A:middle L:90%
to find the right relationship between this principle and that

414
00:25:14.059 --> 00:25:18.849 A:middle L:90%
permission because that would not satisfy our core axiom.

415
00:25:19.640 --> 00:25:23.240 A:middle L:90%
So you could probably imagine taking an access control models

416
00:25:23.240 --> 00:25:26.029 A:middle L:90%
that you're familiar with on file protection systems and imagine

417
00:25:26.029 --> 00:25:29.339 A:middle L:90%
how you could put them in this framework and that

418
00:25:29.339 --> 00:25:32.430 A:middle L:90%
should give you some confidence that yes, this better

419
00:25:32.430 --> 00:25:37.740 A:middle L:90%
model is really capturing concretely and realistically and precisely something

420
00:25:37.740 --> 00:25:45.630 A:middle L:90%
that I'm familiar with. Well, great. So

421
00:25:45.630 --> 00:25:47.859 A:middle L:90%
that's part of the problem solved. We now have

422
00:25:47.859 --> 00:25:52.480 A:middle L:90%
a way of um developing a very precise understanding about

423
00:25:52.480 --> 00:25:55.900 A:middle L:90%
what access control means and that's one of the two

424
00:25:55.900 --> 00:26:00.549 A:middle L:90%
major categories of mechanisms that we're using to ensure confidentiality

425
00:26:00.240 --> 00:26:03.789 A:middle L:90%
. What about the other mechanism about information flow control

426
00:26:03.799 --> 00:26:07.180 A:middle L:90%
and that's where our contribution is coming in. We

427
00:26:07.180 --> 00:26:10.849 A:middle L:90%
want to be able to take barker's framework and see

428
00:26:10.849 --> 00:26:14.829 A:middle L:90%
if we could develop an information flow models. So

429
00:26:14.829 --> 00:26:17.369 A:middle L:90%
our motivation for doing that is all of the same

430
00:26:17.369 --> 00:26:19.670 A:middle L:90%
motivations that barker had because everything that was true about

431
00:26:19.680 --> 00:26:23.279 A:middle L:90%
being able to compare access control models in his framework

432
00:26:23.289 --> 00:26:26.859 A:middle L:90%
, we could compare information flow models in our framework

433
00:26:26.839 --> 00:26:30.230 A:middle L:90%
but in addition we wanted to know is that possible

434
00:26:32.039 --> 00:26:34.390 A:middle L:90%
because he developed that framework for a particular kind of

435
00:26:34.519 --> 00:26:41.980 A:middle L:90%
perspective. Is that framework also adequate to define information

436
00:26:41.980 --> 00:26:45.500 A:middle L:90%
flow control. Can we use categories and relations or

437
00:26:45.589 --> 00:26:48.900 A:middle L:90%
as information flows somehow different and you need a different

438
00:26:48.900 --> 00:26:53.789 A:middle L:90%
kind of underpinning it also allows us if we could

439
00:26:53.789 --> 00:26:56.019 A:middle L:90%
develop this other meta model, we would now have

440
00:26:56.019 --> 00:27:03.630 A:middle L:90%
to meta models for the critical confidentiality mechanisms and we

441
00:27:03.630 --> 00:27:06.680 A:middle L:90%
might want to know how they compare to each other

442
00:27:08.140 --> 00:27:11.970 A:middle L:90%
and to explore possible combinations. What do you get

443
00:27:11.970 --> 00:27:15.079 A:middle L:90%
if you take some of this and some of that

444
00:27:15.079 --> 00:27:17.839 A:middle L:90%
and put it together? Do you get new and

445
00:27:17.839 --> 00:27:21.759 A:middle L:90%
useful things? So that's what our motivation was.

446
00:27:22.740 --> 00:27:26.579 A:middle L:90%
Okay, so what I want to do is is

447
00:27:26.579 --> 00:27:30.609 A:middle L:90%
go through a very simple information flow scenario just because

448
00:27:30.609 --> 00:27:34.750 A:middle L:90%
it helps to um give you some intuition if you're

449
00:27:34.750 --> 00:27:40.380 A:middle L:90%
not familiar with information flow control ideas but also it

450
00:27:40.380 --> 00:27:42.519 A:middle L:90%
will give us a set of basic requirements that our

451
00:27:42.519 --> 00:27:47.289 A:middle L:90%
model needs to include. So here in this uh

452
00:27:47.299 --> 00:27:48.630 A:middle L:90%
this this simple file sharing example. We have are

453
00:27:48.630 --> 00:27:51.720 A:middle L:90%
two principles Alice and bob and there are three files

454
00:27:51.720 --> 00:27:52.470 A:middle L:90%
, A, B and C. And the policy

455
00:27:52.470 --> 00:27:56.200 A:middle L:90%
that we want to enforce is that bob should only

456
00:27:56.200 --> 00:27:57.650 A:middle L:90%
be able to see public information. But Alice could

457
00:27:57.650 --> 00:28:02.759 A:middle L:90%
see information that's either public or private and the contents

458
00:28:02.759 --> 00:28:04.400 A:middle L:90%
of files and whether it's public or private is given

459
00:28:04.400 --> 00:28:08.430 A:middle L:90%
by this simple little color coding. So in one

460
00:28:08.430 --> 00:28:14.569 A:middle L:90%
scenario, imagine that Alice reads from file A and

461
00:28:14.569 --> 00:28:19.160 A:middle L:90%
that's possible because our policy allows Alice to access either

462
00:28:19.160 --> 00:28:22.470 A:middle L:90%
kind of information and Alice may then write that information

463
00:28:22.470 --> 00:28:25.869 A:middle L:90%
to file C. Which is fine because file C

464
00:28:25.869 --> 00:28:29.200 A:middle L:90%
. Is able to contain public information and then bob

465
00:28:29.200 --> 00:28:32.519 A:middle L:90%
could read that information. Okay. So what that

466
00:28:32.519 --> 00:28:34.819 A:middle L:90%
means is in this scenario, bob is able to

467
00:28:34.819 --> 00:28:37.269 A:middle L:90%
read what Alice wrote, bob is able to read

468
00:28:37.269 --> 00:28:41.599 A:middle L:90%
the contents of file C. And implicitly bob is

469
00:28:41.599 --> 00:28:44.720 A:middle L:90%
able to understand or infer something about the contents of

470
00:28:44.720 --> 00:28:48.539 A:middle L:90%
file A because the original information that Alice read was

471
00:28:48.539 --> 00:28:51.970 A:middle L:90%
from filet and it is implicitly being transferred perhaps even

472
00:28:51.970 --> 00:28:55.470 A:middle L:90%
directly and immediately being transferred to bob. But that's

473
00:28:55.470 --> 00:28:59.839 A:middle L:90%
fine because it's all within the it's seen as valid

474
00:28:59.839 --> 00:29:03.289 A:middle L:90%
within our policy framework. Well, here's a different

475
00:29:03.289 --> 00:29:08.259 A:middle L:90%
scenario suppose that Alice reads file b which is private

476
00:29:08.259 --> 00:29:12.660 A:middle L:90%
information and Alice is now in possession of something that

477
00:29:12.660 --> 00:29:18.329 A:middle L:90%
is not public. And so we should really change

478
00:29:18.329 --> 00:29:22.829 A:middle L:90%
our view of Alice's status to reflect the fact that

479
00:29:22.829 --> 00:29:27.569 A:middle L:90%
she now holds private information. If Alice writes that

480
00:29:27.569 --> 00:29:30.650 A:middle L:90%
information to see, we would similarly need to change

481
00:29:30.660 --> 00:29:36.269 A:middle L:90%
. File sees our sense about the sensitivity of what's

482
00:29:36.269 --> 00:29:38.640 A:middle L:90%
in file. See in a similar way. And

483
00:29:38.640 --> 00:29:41.349 A:middle L:90%
in this case bob would not be able to read

484
00:29:41.349 --> 00:29:45.150 A:middle L:90%
from file C. Because bob is not supposed to

485
00:29:45.150 --> 00:29:51.289 A:middle L:90%
have access to private information, bob would not be

486
00:29:51.289 --> 00:29:53.869 A:middle L:90%
able to read what Alice wrote because we don't want

487
00:29:53.869 --> 00:29:56.450 A:middle L:90%
bob to be able to infer anything about the contents

488
00:29:56.940 --> 00:30:00.009 A:middle L:90%
of this file be that has private information in.

489
00:30:02.339 --> 00:30:03.589 A:middle L:90%
So what is that telling us? That's telling us

490
00:30:03.589 --> 00:30:07.700 A:middle L:90%
that in some situations, bob can do certain actions

491
00:30:07.809 --> 00:30:11.619 A:middle L:90%
and in other cases? Not Alright. So in

492
00:30:11.619 --> 00:30:14.690 A:middle L:90%
the first scenario, bob could read the contents of

493
00:30:14.700 --> 00:30:15.400 A:middle L:90%
file, see in the second he could not,

494
00:30:15.700 --> 00:30:18.819 A:middle L:90%
In the first scenario he could read what Alice wrote

495
00:30:18.829 --> 00:30:22.700 A:middle L:90%
in the second scenario. Not in the first scenario

496
00:30:22.700 --> 00:30:25.490 A:middle L:90%
, Alice never really changed her status. She was

497
00:30:25.490 --> 00:30:27.910 A:middle L:90%
always a blue circle. In the second scenario,

498
00:30:27.910 --> 00:30:30.529 A:middle L:90%
she started out being a blue slicker and wound up

499
00:30:30.529 --> 00:30:33.029 A:middle L:90%
being a red circle and the same thing for file

500
00:30:33.029 --> 00:30:34.759 A:middle L:90%
C. Because we were trying to keep track of

501
00:30:36.140 --> 00:30:40.210 A:middle L:90%
whether something held private or public information. So that's

502
00:30:40.210 --> 00:30:45.130 A:middle L:90%
telling us what we need is something that's dynamic as

503
00:30:45.130 --> 00:30:48.920 A:middle L:90%
the system is operating. We need to dynamically determine

504
00:30:48.920 --> 00:30:52.960 A:middle L:90%
whether something is accessible or not. That means we

505
00:30:52.960 --> 00:30:56.099 A:middle L:90%
need some labeling here, we're using this color coding

506
00:30:56.099 --> 00:31:00.410 A:middle L:90%
, but we need some way to label what kind

507
00:31:00.410 --> 00:31:03.980 A:middle L:90%
of information anything is holding at a particular time.

508
00:31:06.740 --> 00:31:08.109 A:middle L:90%
And as we saw here with Alice, we need

509
00:31:08.109 --> 00:31:11.630 A:middle L:90%
at least two different kinds of things to keep track

510
00:31:11.630 --> 00:31:14.059 A:middle L:90%
of in order to express a policy like this.

511
00:31:14.740 --> 00:31:17.509 A:middle L:90%
Right? Because Alice is allowed to read over some

512
00:31:17.509 --> 00:31:23.059 A:middle L:90%
range bob has a more restricted range and where Alice

513
00:31:23.069 --> 00:31:26.220 A:middle L:90%
is in that range at any particular time, changes

514
00:31:26.230 --> 00:31:29.309 A:middle L:90%
over time. So we need at least two things

515
00:31:29.309 --> 00:31:30.470 A:middle L:90%
we need to keep track of. What kind of

516
00:31:30.470 --> 00:31:36.460 A:middle L:90%
information do you hold now and what kind of information

517
00:31:36.839 --> 00:31:38.549 A:middle L:90%
uh might you be able to hold? Are you

518
00:31:38.549 --> 00:31:41.019 A:middle L:90%
allowed to hold? So for Alice we would say

519
00:31:41.019 --> 00:31:47.309 A:middle L:90%
, well uh Alice starts out holding public but could

520
00:31:47.309 --> 00:31:48.470 A:middle L:90%
read private information as well. For bob we would

521
00:31:48.470 --> 00:31:52.250 A:middle L:90%
say he's at the public level and he can only

522
00:31:52.250 --> 00:31:55.799 A:middle L:90%
read public information. Now, one of the things

523
00:31:55.799 --> 00:31:57.359 A:middle L:90%
you might imagine is that different information flow control models

524
00:31:57.359 --> 00:32:00.210 A:middle L:90%
are going to vary widely based on how many levels

525
00:32:00.210 --> 00:32:04.960 A:middle L:90%
there are, what these clearances really look like,

526
00:32:05.640 --> 00:32:08.710 A:middle L:90%
what the space of labels is and how you manage

527
00:32:08.710 --> 00:32:12.769 A:middle L:90%
them. But that's all going to be details.

528
00:32:15.039 --> 00:32:16.490 A:middle L:90%
So how do we build this meta model? What

529
00:32:16.490 --> 00:32:20.849 A:middle L:90%
does that mean? And when you have to have

530
00:32:21.240 --> 00:32:27.069 A:middle L:90%
a dynamic mechanism that keeps track of things like these

531
00:32:27.079 --> 00:32:30.940 A:middle L:90%
labels that change dynamically and you need to have things

532
00:32:30.940 --> 00:32:32.039 A:middle L:90%
like levels and clearances in order to be able to

533
00:32:32.039 --> 00:32:39.049 A:middle L:90%
express the policy probably attributes that you need. Well

534
00:32:39.049 --> 00:32:43.059 A:middle L:90%
, the information flow meta model is more complicated.

535
00:32:43.940 --> 00:32:45.039 A:middle L:90%
So there is a single core axiom that sits at

536
00:32:45.039 --> 00:32:51.470 A:middle L:90%
the top below that. We need something to account

537
00:32:51.470 --> 00:32:53.460 A:middle L:90%
for the fact that there's dynamic things going on.

538
00:32:54.240 --> 00:32:57.670 A:middle L:90%
Right? So what is permitted at this point?

539
00:32:58.140 --> 00:33:00.480 A:middle L:90%
Depends on what's happened before. So we need to

540
00:33:00.480 --> 00:33:04.990 A:middle L:90%
keep track of history. Right? Because remember that

541
00:33:04.990 --> 00:33:07.190 A:middle L:90%
in scenario one Bob was able to do something because

542
00:33:07.190 --> 00:33:13.430 A:middle L:90%
the prior history didn't interfere with that In scenario two

543
00:33:13.430 --> 00:33:15.329 A:middle L:90%
Bob was not able to read from file. See

544
00:33:15.329 --> 00:33:19.940 A:middle L:90%
because what had happened before that reconfigured the system in

545
00:33:19.940 --> 00:33:22.200 A:middle L:90%
such a way that his access to file C should

546
00:33:22.200 --> 00:33:24.349 A:middle L:90%
now not be granted. So we need that history

547
00:33:25.940 --> 00:33:28.369 A:middle L:90%
. Well on top of that history we need to

548
00:33:28.369 --> 00:33:30.190 A:middle L:90%
keep track of okay in this history as it's evolving

549
00:33:30.190 --> 00:33:32.859 A:middle L:90%
what's happening with these levels and clearances. How are

550
00:33:32.859 --> 00:33:36.950 A:middle L:90%
the how is the color coding in that diagram changing

551
00:33:37.940 --> 00:33:39.470 A:middle L:90%
? And if you have information at this level and

552
00:33:39.470 --> 00:33:42.650 A:middle L:90%
information at that level and they flow together, what

553
00:33:42.650 --> 00:33:46.500 A:middle L:90%
do you get as a result? And finally down

554
00:33:46.500 --> 00:33:50.349 A:middle L:90%
at the bottom there's this initialization which is how you

555
00:33:50.349 --> 00:33:52.490 A:middle L:90%
actually specify a particular policy, you give the initial

556
00:33:52.490 --> 00:33:58.930 A:middle L:90%
conditions for the model. Okay. Now what happens

557
00:33:58.930 --> 00:34:04.309 A:middle L:90%
after this is much more selective um on my part

558
00:34:04.319 --> 00:34:06.160 A:middle L:90%
because I want to give you a sense, this

559
00:34:06.160 --> 00:34:07.190 A:middle L:90%
is really the important thing. This is how the

560
00:34:07.190 --> 00:34:10.800 A:middle L:90%
model is organized and what are the challenges this model

561
00:34:10.800 --> 00:34:15.889 A:middle L:90%
has to deal with and how are you, how

562
00:34:15.889 --> 00:34:19.429 A:middle L:90%
are all the relations that are defined to express this

563
00:34:19.429 --> 00:34:21.679 A:middle L:90%
model organized. And so if you want to put

564
00:34:21.679 --> 00:34:23.039 A:middle L:90%
on your systems hat for a minute you can think

565
00:34:23.039 --> 00:34:25.969 A:middle L:90%
about this is this is just a stack. Okay

566
00:34:25.969 --> 00:34:29.010 A:middle L:90%
, this is like a protocol stack, we've got

567
00:34:29.010 --> 00:34:30.150 A:middle L:90%
something at the top that we need to decide and

568
00:34:30.150 --> 00:34:32.230 A:middle L:90%
that thing is going to use all of the relations

569
00:34:32.230 --> 00:34:35.449 A:middle L:90%
that we define here. That thing is going to

570
00:34:35.449 --> 00:34:37.550 A:middle L:90%
use the relations we define here and that thing is

571
00:34:37.550 --> 00:34:39.510 A:middle L:90%
gonna depend on these initialization. Alright. So it's

572
00:34:39.510 --> 00:34:43.300 A:middle L:90%
just it's a you can think about it as a

573
00:34:43.300 --> 00:34:49.800 A:middle L:90%
layered architecture in a very pragmatic way. So what

574
00:34:49.809 --> 00:34:52.940 A:middle L:90%
is the core axiom? The core axiom in this

575
00:34:52.940 --> 00:35:00.659 A:middle L:90%
case reflects the nature of the problem that information flow

576
00:35:00.659 --> 00:35:04.469 A:middle L:90%
control is trying to address. So this core axiom

577
00:35:04.480 --> 00:35:07.440 A:middle L:90%
. So I'll talk about its picture first. The

578
00:35:07.440 --> 00:35:12.300 A:middle L:90%
picture says, should we authorize P to perform some

579
00:35:12.300 --> 00:35:15.250 A:middle L:90%
action on resource are Well, we can if we

580
00:35:15.250 --> 00:35:20.800 A:middle L:90%
can find these relationships if he happens to be in

581
00:35:20.800 --> 00:35:24.360 A:middle L:90%
some category, this category is like a label.

582
00:35:25.340 --> 00:35:29.110 A:middle L:90%
So if he has a particular label. So Alice

583
00:35:29.110 --> 00:35:35.110 A:middle L:90%
had a label like public and the Resource has a

584
00:35:35.110 --> 00:35:37.659 A:middle L:90%
label. So file C had a label like public

585
00:35:39.039 --> 00:35:43.400 A:middle L:90%
. And there is some relation that tells us if

586
00:35:43.400 --> 00:35:47.130 A:middle L:90%
you're doing this action, Does our system allow a

587
00:35:47.130 --> 00:35:52.309 A:middle L:90%
flow of information from one from an entity having this

588
00:35:52.309 --> 00:35:55.650 A:middle L:90%
label to an entity having the other label. And

589
00:35:55.650 --> 00:36:00.159 A:middle L:90%
whichever way this flow goes depends on what this operation

590
00:36:00.170 --> 00:36:02.010 A:middle L:90%
is. If it's a read operation, the flow

591
00:36:02.010 --> 00:36:04.840 A:middle L:90%
goes this way. If it's a write operation of

592
00:36:04.849 --> 00:36:08.230 A:middle L:90%
Flow goes that way. So that's all the core

593
00:36:08.230 --> 00:36:12.480 A:middle L:90%
axiom says. It says if the principal has a

594
00:36:12.480 --> 00:36:15.050 A:middle L:90%
certain label and the resource has a certain label and

595
00:36:15.050 --> 00:36:20.030 A:middle L:90%
it's allowed that an information flow between those labels is

596
00:36:20.030 --> 00:36:23.590 A:middle L:90%
permitted based on the direction implied by a then it's

597
00:36:23.590 --> 00:36:30.719 A:middle L:90%
fine. So if bob is in the category public

598
00:36:30.719 --> 00:36:32.070 A:middle L:90%
and the file C is in the category of public

599
00:36:32.099 --> 00:36:36.639 A:middle L:90%
. And we say that it's allowable for public information

600
00:36:36.639 --> 00:36:38.309 A:middle L:90%
to flow to public information, then fine, bob

601
00:36:38.309 --> 00:36:45.030 A:middle L:90%
can read file a So that part is pretty straightforward

602
00:36:45.030 --> 00:36:46.630 A:middle L:90%
and you can immediately see if you can remember back

603
00:36:46.630 --> 00:36:51.659 A:middle L:90%
to what the core axiom for access control. Was

604
00:36:52.030 --> 00:36:53.670 A:middle L:90%
. This is a very different formulation, right?

605
00:36:53.670 --> 00:36:57.480 A:middle L:90%
It still uses the basic underpinnings. We have categories

606
00:36:57.670 --> 00:37:00.460 A:middle L:90%
and we've got relations. We just added one new

607
00:37:00.460 --> 00:37:02.369 A:middle L:90%
category here. This set of labels and we have

608
00:37:02.369 --> 00:37:05.579 A:middle L:90%
a different set of relations, but we have the

609
00:37:05.579 --> 00:37:09.500 A:middle L:90%
same basic sort of mathematical underpinning to it. But

610
00:37:09.500 --> 00:37:13.119 A:middle L:90%
because it's answering a different question, those relations are

611
00:37:13.119 --> 00:37:16.840 A:middle L:90%
really organized in a very different way. Alright.

612
00:37:16.840 --> 00:37:19.719 A:middle L:90%
Well, how do we keep track of history?

613
00:37:19.730 --> 00:37:22.929 A:middle L:90%
We have to know because what Alice is doing is

614
00:37:22.929 --> 00:37:24.570 A:middle L:90%
going to influence what bob is capable of doing in

615
00:37:24.570 --> 00:37:27.230 A:middle L:90%
the future. How do we keep track of the

616
00:37:27.239 --> 00:37:30.579 A:middle L:90%
history? And it's visually, it's easy to see

617
00:37:30.579 --> 00:37:34.949 A:middle L:90%
what we have to do. Well, we have

618
00:37:34.949 --> 00:37:37.889 A:middle L:90%
to know what happened. So, we need some

619
00:37:37.889 --> 00:37:40.739 A:middle L:90%
formal way of reasoning about what happened and the things

620
00:37:40.739 --> 00:37:45.070 A:middle L:90%
that we are interested in is what did we allow

621
00:37:45.070 --> 00:37:49.230 A:middle L:90%
to happen previously? Because all of that history influences

622
00:37:49.230 --> 00:37:52.489 A:middle L:90%
the decision that we have to make now. So

623
00:37:52.489 --> 00:37:53.929 A:middle L:90%
here, at time. T the critical question is

624
00:37:55.190 --> 00:38:00.130 A:middle L:90%
if I'm looking at a principal, what label does

625
00:38:00.130 --> 00:38:01.699 A:middle L:90%
that principle have? If I'm looking at Alice,

626
00:38:01.710 --> 00:38:06.369 A:middle L:90%
is Alice at that point in time, is Alice's

627
00:38:06.369 --> 00:38:08.679 A:middle L:90%
label public? Or is Alice's label private? Because

628
00:38:08.679 --> 00:38:10.440 A:middle L:90%
that's going to make a difference to what Alice can

629
00:38:10.440 --> 00:38:15.340 A:middle L:90%
do. And similarly, for the Resource, we

630
00:38:15.340 --> 00:38:16.019 A:middle L:90%
need to be able to argue the same thing for

631
00:38:16.019 --> 00:38:17.980 A:middle L:90%
the resource. So what do we do? Well

632
00:38:17.980 --> 00:38:21.400 A:middle L:90%
, we just have a timeline and every time we

633
00:38:21.400 --> 00:38:25.360 A:middle L:90%
allow something to happen This granted means that we allowed

634
00:38:25.369 --> 00:38:30.380 A:middle L:90%
at time T one P which has this label to

635
00:38:30.380 --> 00:38:32.480 A:middle L:90%
access our where are had that label. That was

636
00:38:32.489 --> 00:38:36.369 A:middle L:90%
something that we authorized in the past. And we

637
00:38:36.380 --> 00:38:37.449 A:middle L:90%
just keep track of all the things that we've authorized

638
00:38:38.420 --> 00:38:40.239 A:middle L:90%
. So, if we want to know what's true

639
00:38:40.239 --> 00:38:45.230 A:middle L:90%
here, what label does Alice have? Well,

640
00:38:45.230 --> 00:38:47.639 A:middle L:90%
we just have to look backward in time and find

641
00:38:47.639 --> 00:38:52.360 A:middle L:90%
out well, what's affecting what what what has Alice

642
00:38:52.360 --> 00:38:57.539 A:middle L:90%
done previously. Right. So, in this history

643
00:38:57.539 --> 00:38:59.480 A:middle L:90%
, we would look back and say, well,

644
00:38:59.480 --> 00:39:01.219 A:middle L:90%
this doesn't matter because this is something that we did

645
00:39:01.219 --> 00:39:05.960 A:middle L:90%
for some other principles can't affect Alice. Well,

646
00:39:05.960 --> 00:39:07.590 A:middle L:90%
earlier Alice, we allowed Alice to do this,

647
00:39:07.599 --> 00:39:10.340 A:middle L:90%
and more recently, we allowed Alice to do this

648
00:39:10.500 --> 00:39:13.440 A:middle L:90%
. So between those two, the ones that we

649
00:39:13.440 --> 00:39:15.340 A:middle L:90%
obviously want to use is the more recent ones.

650
00:39:15.019 --> 00:39:16.400 A:middle L:90%
In fact, what we want to do is to

651
00:39:16.400 --> 00:39:20.199 A:middle L:90%
start from this point and go backward and find the

652
00:39:20.199 --> 00:39:22.250 A:middle L:90%
most recent thing that we allowed Alice to do and

653
00:39:22.250 --> 00:39:24.909 A:middle L:90%
ask when we allowed Alice to do that, what

654
00:39:24.909 --> 00:39:29.340 A:middle L:90%
label did Alice have as a result of being able

655
00:39:29.340 --> 00:39:34.480 A:middle L:90%
to do that? Because whatever label Alice had after

656
00:39:34.480 --> 00:39:37.159 A:middle L:90%
this operation, if that was the last operation,

657
00:39:37.329 --> 00:39:38.769 A:middle L:90%
that's the label that Alice had now, because nothing

658
00:39:38.769 --> 00:39:42.480 A:middle L:90%
else the system did would affect the label that Alice

659
00:39:42.480 --> 00:39:45.789 A:middle L:90%
had. How do you do that mathematically? Well

660
00:39:45.789 --> 00:39:47.039 A:middle L:90%
, you get a bunch of stuff like this.

661
00:39:50.420 --> 00:39:53.190 A:middle L:90%
It's just being careful and precise about what does it

662
00:39:53.190 --> 00:39:55.590 A:middle L:90%
mean? So, I only want to show you

663
00:39:55.590 --> 00:39:59.840 A:middle L:90%
the tip of the iceberg on what's here. So

664
00:40:00.809 --> 00:40:02.690 A:middle L:90%
what we want to know is what's the label associated

665
00:40:02.690 --> 00:40:06.639 A:middle L:90%
with a principal? What label does Alice have?

666
00:40:07.409 --> 00:40:09.340 A:middle L:90%
Well, what we really want to know is I

667
00:40:09.340 --> 00:40:12.170 A:middle L:90%
want to look back into history and look at what

668
00:40:12.170 --> 00:40:14.389 A:middle L:90%
label Alice had at different points in time. And

669
00:40:14.389 --> 00:40:15.829 A:middle L:90%
then what I'm interested in is the current time.

670
00:40:16.409 --> 00:40:22.730 A:middle L:90%
That's what I really want to know. And so

671
00:40:22.730 --> 00:40:24.650 A:middle L:90%
we can start looking back through that history and when

672
00:40:24.650 --> 00:40:27.820 A:middle L:90%
somebody develops a policy while they have to tell us

673
00:40:27.820 --> 00:40:30.030 A:middle L:90%
what's true at time zero, they have to give

674
00:40:30.030 --> 00:40:34.039 A:middle L:90%
us some initial label for Alice. And the rest

675
00:40:34.039 --> 00:40:36.170 A:middle L:90%
of this in between is just saying, well,

676
00:40:36.170 --> 00:40:37.349 A:middle L:90%
okay, if you really want to know what label

677
00:40:37.349 --> 00:40:40.559 A:middle L:90%
Alice has at time. T here's how you find

678
00:40:40.559 --> 00:40:43.559 A:middle L:90%
out, right? And there are different cases,

679
00:40:43.559 --> 00:40:45.829 A:middle L:90%
depending on what what kind of operation Alice did.

680
00:40:46.610 --> 00:40:50.679 A:middle L:90%
Um just to be very quick about this. What

681
00:40:50.690 --> 00:40:53.960 A:middle L:90%
this one means is look back in that history of

682
00:40:53.960 --> 00:40:59.389 A:middle L:90%
what's happened about things you've granted earlier and find a

683
00:40:59.389 --> 00:41:01.949 A:middle L:90%
point in time where you allowed Alice to do something

684
00:41:01.960 --> 00:41:06.110 A:middle L:90%
that's the closest to the current time. And if

685
00:41:06.110 --> 00:41:08.489 A:middle L:90%
what Alice was doing was a mutate operation. That

686
00:41:08.489 --> 00:41:14.030 A:middle L:90%
is an operation that was flowing information out from Alice

687
00:41:14.610 --> 00:41:17.579 A:middle L:90%
then, oh and this is the most recent time

688
00:41:17.639 --> 00:41:20.769 A:middle L:90%
then the label that Alice has now is the same

689
00:41:20.769 --> 00:41:22.300 A:middle L:90%
as the one that Alice had then. Because this

690
00:41:22.300 --> 00:41:27.590 A:middle L:90%
mutate operation wouldn't have changed her label if she did

691
00:41:27.590 --> 00:41:29.860 A:middle L:90%
. And another kind of operation, then you've got

692
00:41:29.860 --> 00:41:30.820 A:middle L:90%
to figure out what her new label is based on

693
00:41:30.820 --> 00:41:34.130 A:middle L:90%
the labels that she had then and whatever she read

694
00:41:34.139 --> 00:41:37.639 A:middle L:90%
from. So that's how we deal with the history

695
00:41:38.409 --> 00:41:44.900 A:middle L:90%
. The next layer down is um to be able

696
00:41:45.260 --> 00:41:45.960 A:middle L:90%
to see for example that here we have used an

697
00:41:45.960 --> 00:41:53.349 A:middle L:90%
operation combining because when Alice is currently remembering that scenario

698
00:41:53.349 --> 00:41:57.559 A:middle L:90%
, Alice had a public label. She read from

699
00:41:57.570 --> 00:42:00.480 A:middle L:90%
a private file. And her her label then changed

700
00:42:00.480 --> 00:42:02.860 A:middle L:90%
to be private to reflect the fact that she's holding

701
00:42:02.860 --> 00:42:07.429 A:middle L:90%
private information. Right? That's what this operation does

702
00:42:08.099 --> 00:42:10.690 A:middle L:90%
right? If I'm if I'm public now and I'm

703
00:42:10.690 --> 00:42:13.809 A:middle L:90%
reading this private thing, what's my new label?

704
00:42:14.400 --> 00:42:15.719 A:middle L:90%
Well in that case it's easy, it's private.

705
00:42:16.699 --> 00:42:22.190 A:middle L:90%
But we haven't defined this operation because that's an operation

706
00:42:22.190 --> 00:42:27.119 A:middle L:90%
that involves how do we combine these labels And that's

707
00:42:27.119 --> 00:42:29.059 A:middle L:90%
what our next layer down is what we have to

708
00:42:29.059 --> 00:42:31.380 A:middle L:90%
deal with labels levels and clearances. And so there's

709
00:42:31.380 --> 00:42:37.579 A:middle L:90%
a bunch of stuff to do that. And so

710
00:42:37.590 --> 00:42:44.429 A:middle L:90%
um what does one of this mean? So these

711
00:42:44.429 --> 00:42:47.719 A:middle L:90%
two things are just different because There's two types of

712
00:42:47.719 --> 00:42:52.309 A:middle L:90%
operations that information flow really focuses on. It really

713
00:42:52.309 --> 00:42:54.849 A:middle L:90%
focuses on whether the information flow is going from the

714
00:42:54.849 --> 00:42:57.730 A:middle L:90%
principal to the resource or from the resource of the

715
00:42:57.730 --> 00:43:00.539 A:middle L:90%
princess. There's lots of operations that can do either

716
00:43:00.539 --> 00:43:04.659 A:middle L:90%
one of those. So you just have to change

717
00:43:04.659 --> 00:43:06.050 A:middle L:90%
who you think is the source and who you think

718
00:43:06.050 --> 00:43:07.329 A:middle L:90%
is the destination depending on which way the flow is

719
00:43:07.329 --> 00:43:12.260 A:middle L:90%
going. What is the operator imply? And then

720
00:43:12.260 --> 00:43:14.190 A:middle L:90%
once you figured out the flow then you just have

721
00:43:14.190 --> 00:43:15.929 A:middle L:90%
to ask, well is it okay for there to

722
00:43:15.929 --> 00:43:17.469 A:middle L:90%
be a flow from here to there, depending on

723
00:43:17.469 --> 00:43:25.360 A:middle L:90%
different cases, ignore the details. This is the

724
00:43:25.360 --> 00:43:28.739 A:middle L:90%
combined operation that we looked at earlier. How do

725
00:43:28.739 --> 00:43:32.030 A:middle L:90%
we take to labels and combine them together when we

726
00:43:32.030 --> 00:43:35.809 A:middle L:90%
want each label to be have A level and it

727
00:43:35.809 --> 00:43:37.739 A:middle L:90%
also has a clearance. How do we work that

728
00:43:37.739 --> 00:43:39.960 A:middle L:90%
out? Well, we just kind of combined them

729
00:43:39.960 --> 00:43:45.550 A:middle L:90%
together but it depends on another undefined operation. This

730
00:43:45.550 --> 00:43:47.230 A:middle L:90%
joint operation, it says, if you have two

731
00:43:47.230 --> 00:43:50.230 A:middle L:90%
things like this, what does it mean to put

732
00:43:50.239 --> 00:43:55.099 A:middle L:90%
them together. Alright. And so here is our

733
00:43:55.099 --> 00:44:00.530 A:middle L:90%
model again. Right. And here's the various operations

734
00:44:00.530 --> 00:44:04.369 A:middle L:90%
or relations that we've seen at these various layers.

735
00:44:04.380 --> 00:44:06.500 A:middle L:90%
So here's the core axiom that's sitting up at the

736
00:44:06.500 --> 00:44:12.269 A:middle L:90%
top here, this history involved knowing whether the time

737
00:44:12.269 --> 00:44:14.539 A:middle L:90%
is the current time, what happened in the history

738
00:44:14.539 --> 00:44:16.860 A:middle L:90%
, whether this was the most recent event that happened

739
00:44:16.949 --> 00:44:22.719 A:middle L:90%
these time dependent versions of the labels for a principal

740
00:44:22.719 --> 00:44:24.750 A:middle L:90%
and a resource that allowed us then to figure these

741
00:44:24.750 --> 00:44:29.389 A:middle L:90%
things out. This thing depended on this combined operation

742
00:44:29.389 --> 00:44:30.730 A:middle L:90%
that we saw. That combined operation depends on this

743
00:44:30.730 --> 00:44:34.650 A:middle L:90%
joint operation. Right. And so if you wanted

744
00:44:34.650 --> 00:44:36.510 A:middle L:90%
to find a policy, what you have to do

745
00:44:36.510 --> 00:44:39.190 A:middle L:90%
is to specify all of these things, what does

746
00:44:39.190 --> 00:44:40.860 A:middle L:90%
that mean? It means you have to define,

747
00:44:40.860 --> 00:44:45.500 A:middle L:90%
well, what are my categories of levels and clearances

748
00:44:45.690 --> 00:44:50.219 A:middle L:90%
? How do I join them together when information with

749
00:44:50.219 --> 00:44:52.710 A:middle L:90%
these different levels and clearances combined? How do I

750
00:44:53.389 --> 00:44:58.369 A:middle L:90%
, what's the result of that? If I have

751
00:44:58.380 --> 00:45:00.539 A:middle L:90%
things with two different labels, can information flow from

752
00:45:00.539 --> 00:45:01.139 A:middle L:90%
one to the other? Yes or no. I

753
00:45:01.139 --> 00:45:04.809 A:middle L:90%
mean, tell me what's legitimate in this system,

754
00:45:05.889 --> 00:45:08.409 A:middle L:90%
describe your operations and tell me which one's which way

755
00:45:08.409 --> 00:45:12.750 A:middle L:90%
the flow goes for this particular operation. And tell

756
00:45:12.750 --> 00:45:14.699 A:middle L:90%
me what the initial assignment of labels is. Once

757
00:45:14.699 --> 00:45:15.900 A:middle L:90%
you have that, then the rest of this mechanism

758
00:45:15.900 --> 00:45:22.679 A:middle L:90%
kicks in and everything sort of happened. So that's

759
00:45:22.679 --> 00:45:25.719 A:middle L:90%
the model structure And here is our little example with

760
00:45:25.730 --> 00:45:29.010 A:middle L:90%
with bob and Alice and the files. This is

761
00:45:29.010 --> 00:45:32.599 A:middle L:90%
what it would look like to define a policy that

762
00:45:32.599 --> 00:45:37.340 A:middle L:90%
we used before. We have to define our principles

763
00:45:37.340 --> 00:45:37.750 A:middle L:90%
. So it's Alice and bob, we have to

764
00:45:37.750 --> 00:45:40.030 A:middle L:90%
define our resources, A, B and C.

765
00:45:40.269 --> 00:45:44.719 A:middle L:90%
We have two actions. Read and write. The

766
00:45:44.730 --> 00:45:46.340 A:middle L:90%
write operation is a mutate, which means that the

767
00:45:46.340 --> 00:45:51.030 A:middle L:90%
flow goes from the principal to the resource. The

768
00:45:51.030 --> 00:45:53.579 A:middle L:90%
read is an inspect operation where the flow goes from

769
00:45:53.579 --> 00:45:58.119 A:middle L:90%
the resource to the principal. And here we are

770
00:45:58.119 --> 00:46:00.519 A:middle L:90%
defining what are the legitimate flows. It's fine for

771
00:46:00.519 --> 00:46:02.619 A:middle L:90%
public to flow to public. Public to flow to

772
00:46:02.619 --> 00:46:07.500 A:middle L:90%
private and private to flow to private. Note The

773
00:46:07.500 --> 00:46:09.829 A:middle L:90%
missing one is you cannot have a flow that goes

774
00:46:09.829 --> 00:46:15.599 A:middle L:90%
from private to public. Here's how you combine these

775
00:46:15.599 --> 00:46:19.099 A:middle L:90%
various labels of public source and a public destination.

776
00:46:19.099 --> 00:46:22.000 A:middle L:90%
Well, the result is public right and so on

777
00:46:22.179 --> 00:46:27.710 A:middle L:90%
. So when Alice who is currently labeled public reads

778
00:46:27.710 --> 00:46:32.900 A:middle L:90%
private information analysis label must change to private. Why

779
00:46:32.980 --> 00:46:36.090 A:middle L:90%
? Well, because that's the policy we're defining,

780
00:46:36.679 --> 00:46:37.710 A:middle L:90%
we're just saying this is the way our system works

781
00:46:42.579 --> 00:46:44.699 A:middle L:90%
. Alright. So what do we get by having

782
00:46:44.699 --> 00:46:49.150 A:middle L:90%
done this work? So what um Well we've satisfied

783
00:46:49.150 --> 00:46:52.519 A:middle L:90%
our academic obligation. We published a paper have we

784
00:46:52.519 --> 00:46:54.150 A:middle L:90%
advanced the state of knowledge? Well that's what maybe

785
00:46:54.150 --> 00:46:58.010 A:middle L:90%
this is. So first of all, the framework

786
00:46:58.010 --> 00:47:00.039 A:middle L:90%
that barker developed is perfectly adequate for information flow as

787
00:47:00.039 --> 00:47:02.719 A:middle L:90%
well. We're just using categories and relations and it's

788
00:47:02.719 --> 00:47:07.019 A:middle L:90%
very closely modeled whenever possible on the framework that he

789
00:47:07.019 --> 00:47:09.679 A:middle L:90%
built for Access control. We can see some interesting

790
00:47:09.679 --> 00:47:14.849 A:middle L:90%
differences between access control and information flow control. Access

791
00:47:14.849 --> 00:47:16.489 A:middle L:90%
control is very explicit about the permission it gives,

792
00:47:16.489 --> 00:47:21.960 A:middle L:90%
you says you can write to that file but you

793
00:47:21.960 --> 00:47:24.139 A:middle L:90%
may not be able to append to that file because

794
00:47:24.139 --> 00:47:27.429 A:middle L:90%
that's a different operation if you want to append to

795
00:47:27.429 --> 00:47:30.610 A:middle L:90%
that file, I need a different permission. Information

796
00:47:30.610 --> 00:47:34.030 A:middle L:90%
flow doesn't care there's information if it's going to flow

797
00:47:34.030 --> 00:47:35.389 A:middle L:90%
into that file, I don't care how you do

798
00:47:35.389 --> 00:47:37.019 A:middle L:90%
it, I'm going to tell you whether you can

799
00:47:37.019 --> 00:47:37.880 A:middle L:90%
do it or not and how you do it and

800
00:47:37.880 --> 00:47:43.670 A:middle L:90%
I don't care, use whatever operation you want and

801
00:47:43.670 --> 00:47:45.329 A:middle L:90%
that's what this idea is about action. Granularity.

802
00:47:45.340 --> 00:47:50.599 A:middle L:90%
Okay, The information flow only cares about the direction

803
00:47:50.599 --> 00:47:52.289 A:middle L:90%
. It really doesn't care about the specific operation that's

804
00:47:52.289 --> 00:47:54.409 A:middle L:90%
implied. So, another way of saying that is

805
00:47:54.409 --> 00:47:57.420 A:middle L:90%
you can define an information flow model with only two

806
00:47:57.420 --> 00:48:01.030 A:middle L:90%
operations. Inspector mutate because you just it's one flow

807
00:48:01.030 --> 00:48:06.670 A:middle L:90%
or the other. Uh Information flow control is a

808
00:48:06.670 --> 00:48:08.940 A:middle L:90%
much more complex thing. We need a lot more

809
00:48:08.940 --> 00:48:15.480 A:middle L:90%
machinery to express information flow control. Remember access control

810
00:48:15.480 --> 00:48:22.130 A:middle L:90%
is one axiom. one core axiom in the information

811
00:48:22.130 --> 00:48:25.199 A:middle L:90%
flow case we need all of this stuff. Although

812
00:48:25.199 --> 00:48:29.429 A:middle L:90%
there's an interesting question about what is the meta model

813
00:48:29.800 --> 00:48:31.579 A:middle L:90%
exactly. And we don't quite know that yet is

814
00:48:31.579 --> 00:48:34.320 A:middle L:90%
the meta model. Just this and the rest of

815
00:48:34.320 --> 00:48:37.550 A:middle L:90%
this is some specialization is the meta model really.

816
00:48:37.550 --> 00:48:42.670 A:middle L:90%
This including the history and this is just specialization and

817
00:48:42.670 --> 00:48:46.780 A:middle L:90%
maybe there are alternative specializations that this layer. We

818
00:48:46.780 --> 00:48:50.039 A:middle L:90%
don't quite know yet. So we don't really have

819
00:48:50.039 --> 00:48:52.820 A:middle L:90%
a firm answer yet to what is the meta model

820
00:48:53.320 --> 00:48:57.280 A:middle L:90%
? that's part of the work to do. History

821
00:48:57.280 --> 00:48:59.670 A:middle L:90%
is definitely required for information flow control. You've got

822
00:48:59.670 --> 00:49:00.610 A:middle L:90%
to have some sort of history because it's dynamic.

823
00:49:00.610 --> 00:49:06.800 A:middle L:90%
Access control is not you don't need that. Here

824
00:49:06.809 --> 00:49:08.880 A:middle L:90%
are here's some hypothesis. This is telling you kind

825
00:49:08.880 --> 00:49:13.789 A:middle L:90%
of more what we don't know. So we want

826
00:49:13.789 --> 00:49:15.989 A:middle L:90%
to know how access control and information flow control compared

827
00:49:15.989 --> 00:49:20.429 A:middle L:90%
to each other. I think this so this is

828
00:49:20.429 --> 00:49:23.260 A:middle L:90%
hypothesis is what I think if you just look at

829
00:49:23.260 --> 00:49:29.489 A:middle L:90%
the core axioms and you discard everything else, they're

830
00:49:29.489 --> 00:49:32.500 A:middle L:90%
the same. They're just different formulations of the same

831
00:49:32.500 --> 00:49:36.489 A:middle L:90%
thing. You can't really tell at that level that

832
00:49:36.489 --> 00:49:38.400 A:middle L:90%
there's any difference. It's only when you add in

833
00:49:38.869 --> 00:49:43.440 A:middle L:90%
the history and begin to interpret some of those operations

834
00:49:43.690 --> 00:49:47.139 A:middle L:90%
that you get some differentiation. Now, what this

835
00:49:47.139 --> 00:49:51.750 A:middle L:90%
picture is suggesting over here is another model that barker

836
00:49:51.750 --> 00:49:54.340 A:middle L:90%
developed was a thing called status based access control where

837
00:49:54.340 --> 00:49:59.159 A:middle L:90%
he included a history but it was it was a

838
00:49:59.159 --> 00:50:01.619 A:middle L:90%
history that was only about the principle. They only

839
00:50:01.619 --> 00:50:06.630 A:middle L:90%
kept track of a history for principles because they wanted

840
00:50:06.630 --> 00:50:07.480 A:middle L:90%
to keep track of the status of those principles.

841
00:50:07.489 --> 00:50:09.429 A:middle L:90%
Did they have a particular status at some point in

842
00:50:09.429 --> 00:50:14.780 A:middle L:90%
time and that was definitely a specific kind of access

843
00:50:14.780 --> 00:50:17.230 A:middle L:90%
control but you needed to add a history mechanism to

844
00:50:17.230 --> 00:50:21.179 A:middle L:90%
it. Well with information flow control, the way

845
00:50:21.179 --> 00:50:24.150 A:middle L:90%
we've defined it is you get a history not only

846
00:50:24.150 --> 00:50:27.570 A:middle L:90%
of principles but of resources. So it should be

847
00:50:27.570 --> 00:50:31.869 A:middle L:90%
the case that this is more powerful than that because

848
00:50:31.869 --> 00:50:36.119 A:middle L:90%
we're keeping track of more stuff. We could express

849
00:50:36.130 --> 00:50:37.389 A:middle L:90%
policies over here that refer to the history of resources

850
00:50:37.389 --> 00:50:39.710 A:middle L:90%
that can't be expressed over there. But anything you

851
00:50:39.710 --> 00:50:42.489 A:middle L:90%
could express over here we should be able to do

852
00:50:43.559 --> 00:50:46.250 A:middle L:90%
. That's a hypothesis. What about these other things

853
00:50:46.630 --> 00:50:50.099 A:middle L:90%
right now that you start to see these pieces?

854
00:50:50.099 --> 00:50:52.949 A:middle L:90%
What other ways could those pieces be combined? So

855
00:50:52.949 --> 00:50:54.429 A:middle L:90%
what if you took access control and put a resource

856
00:50:54.429 --> 00:51:00.010 A:middle L:90%
history along with it? Is that interesting? You

857
00:51:00.010 --> 00:51:02.679 A:middle L:90%
could always come up with some cockamamie policy but is

858
00:51:02.679 --> 00:51:06.670 A:middle L:90%
it interesting? Does that fill some gap that we've

859
00:51:06.679 --> 00:51:08.780 A:middle L:90%
always had but didn't know how to deal with or

860
00:51:08.780 --> 00:51:12.199 A:middle L:90%
if you took information flow control and only did a

861
00:51:12.199 --> 00:51:14.780 A:middle L:90%
history of resources not principles. What would you get

862
00:51:15.659 --> 00:51:17.900 A:middle L:90%
right? Because it's not as powerful as this,

863
00:51:17.900 --> 00:51:21.420 A:middle L:90%
but it's more powerful than this. But what is

864
00:51:21.420 --> 00:51:25.690 A:middle L:90%
it exactly? Is it useful? Does it give

865
00:51:25.690 --> 00:51:30.179 A:middle L:90%
us our next 700 papers? Right. Because we

866
00:51:30.179 --> 00:51:31.579 A:middle L:90%
just keep combining these things in different ways and writing

867
00:51:32.059 --> 00:51:38.179 A:middle L:90%
writing papers about the combination or this is just this

868
00:51:38.179 --> 00:51:42.079 A:middle L:90%
is the core axiom for the access control. Here's

869
00:51:42.079 --> 00:51:44.719 A:middle L:90%
what it is and here is the core axiom for

870
00:51:44.719 --> 00:51:47.059 A:middle L:90%
information Flow control. So what happens if we now

871
00:51:47.059 --> 00:51:50.980 A:middle L:90%
think about adding those two things together? Alright,

872
00:51:50.989 --> 00:51:53.780 A:middle L:90%
because confidentiality is not just about what you can access

873
00:51:53.789 --> 00:51:55.070 A:middle L:90%
, it's about what you can do with it.

874
00:51:55.659 --> 00:51:58.739 A:middle L:90%
So you need a little bit of both. You

875
00:51:58.739 --> 00:52:00.949 A:middle L:90%
need some access control to say can you look at

876
00:52:00.949 --> 00:52:02.650 A:middle L:90%
this thing and some information flow control to say once

877
00:52:02.650 --> 00:52:05.360 A:middle L:90%
you've looked at it, what can you do with

878
00:52:05.360 --> 00:52:07.710 A:middle L:90%
it? Who could you share it with? So

879
00:52:07.710 --> 00:52:09.519 A:middle L:90%
what do we get if we try to combine those

880
00:52:09.519 --> 00:52:15.769 A:middle L:90%
things? We don't know. Right? I'm not

881
00:52:15.769 --> 00:52:17.000 A:middle L:90%
sure we've been in a position to really ask that

882
00:52:17.000 --> 00:52:20.400 A:middle L:90%
question yet, because we haven't been in a position

883
00:52:20.400 --> 00:52:22.090 A:middle L:90%
to see really clearly, oh this is what that

884
00:52:22.090 --> 00:52:23.360 A:middle L:90%
is, and this is what this is. And

885
00:52:23.360 --> 00:52:25.699 A:middle L:90%
now how do we combine them? And you?

886
00:52:25.710 --> 00:52:29.110 A:middle L:90%
And you can see there are perfectly compatible because you

887
00:52:29.110 --> 00:52:31.920 A:middle L:90%
could say the only time you could do something,

888
00:52:31.920 --> 00:52:35.519 A:middle L:90%
the only time you're authorized to do something is if

889
00:52:35.519 --> 00:52:38.340 A:middle L:90%
this says you can and this says it's also allowed

890
00:52:39.449 --> 00:52:42.619 A:middle L:90%
. Alright. So it's conceptually at the high level

891
00:52:42.630 --> 00:52:45.110 A:middle L:90%
, easy to combine them. But you get other

892
00:52:45.110 --> 00:52:49.519 A:middle L:90%
interesting questions. So here it's talking about open versus

893
00:52:49.519 --> 00:52:51.880 A:middle L:90%
closed systems. So a closed system is one that

894
00:52:51.880 --> 00:52:53.780 A:middle L:90%
says you cannot do anything unless I explicitly say you

895
00:52:53.780 --> 00:52:59.190 A:middle L:90%
can, an open system is one that says you

896
00:52:59.190 --> 00:53:01.389 A:middle L:90%
can do anything that you want unless I say you

897
00:53:01.400 --> 00:53:07.269 A:middle L:90%
can't. So a library is like an open system

898
00:53:07.949 --> 00:53:08.119 A:middle L:90%
, right? You can go into the library and

899
00:53:08.119 --> 00:53:09.389 A:middle L:90%
do anything you want, you can look at any

900
00:53:09.389 --> 00:53:12.320 A:middle L:90%
book you want except you can't go into the reserve

901
00:53:12.320 --> 00:53:15.269 A:middle L:90%
collection because I explicitly said you can't go in there

902
00:53:15.650 --> 00:53:19.480 A:middle L:90%
because I put a locked door closed systems are like

903
00:53:19.480 --> 00:53:21.920 A:middle L:90%
UNIX file systems. You can't access this file unless

904
00:53:21.920 --> 00:53:23.070 A:middle L:90%
I explicitly say you can one way or the other

905
00:53:23.650 --> 00:53:25.690 A:middle L:90%
. Well what happens if you try and combine a

906
00:53:25.690 --> 00:53:30.869 A:middle L:90%
closed access control system in an open information flow control

907
00:53:30.869 --> 00:53:34.710 A:middle L:90%
system or an open access control system in a closed

908
00:53:34.710 --> 00:53:37.900 A:middle L:90%
information flow control systems? Do you get interesting policies

909
00:53:37.900 --> 00:53:39.699 A:middle L:90%
, Are there things that we want to be able

910
00:53:39.699 --> 00:53:45.210 A:middle L:90%
to build for android devices for smartphones? For cloud

911
00:53:45.210 --> 00:53:47.739 A:middle L:90%
computing? For all of the new information share for

912
00:53:47.739 --> 00:53:52.489 A:middle L:90%
facebook or google circles? Are there policies that we

913
00:53:52.489 --> 00:53:55.269 A:middle L:90%
want to express about the confidentiality of information that this

914
00:53:55.269 --> 00:54:00.050 A:middle L:90%
now gives us some perspective or being able to identify

915
00:54:02.639 --> 00:54:09.309 A:middle L:90%
. Okay, so future work um we want to

916
00:54:09.320 --> 00:54:12.760 A:middle L:90%
play with the stuff that we've developed. Alright,

917
00:54:12.760 --> 00:54:15.170 A:middle L:90%
so we want to develop specializations for different kinds of

918
00:54:15.170 --> 00:54:19.090 A:middle L:90%
information flow models to see if did we get it

919
00:54:19.090 --> 00:54:22.349 A:middle L:90%
right. That is if there are six information flow

920
00:54:22.349 --> 00:54:24.449 A:middle L:90%
models. Can we see how to specialize our model

921
00:54:24.449 --> 00:54:30.019 A:middle L:90%
for each one of them? Um Can we develop

922
00:54:30.019 --> 00:54:31.119 A:middle L:90%
extensions to our model to incorporate other things. One

923
00:54:31.119 --> 00:54:35.559 A:middle L:90%
of the things we're interested in is community oriented control

924
00:54:35.940 --> 00:54:38.260 A:middle L:90%
. How would that look like in this model?

925
00:54:39.539 --> 00:54:43.079 A:middle L:90%
I want to be able to do continues comparisons with

926
00:54:43.079 --> 00:54:45.739 A:middle L:90%
Access control, explore this design space that I've talked

927
00:54:45.750 --> 00:54:51.860 A:middle L:90%
a little bit about. Um We want to develop

928
00:54:51.869 --> 00:54:54.400 A:middle L:90%
computational realization. So this is all in a computational

929
00:54:54.400 --> 00:54:57.690 A:middle L:90%
logic sort of framework. So can we take some

930
00:54:57.690 --> 00:55:00.420 A:middle L:90%
tools build our model into those tools and use that

931
00:55:00.420 --> 00:55:05.969 A:middle L:90%
to explore properties of policies or systems or to serve

932
00:55:05.969 --> 00:55:07.550 A:middle L:90%
as a prototyping mechanism for systems that we want to

933
00:55:07.559 --> 00:55:10.150 A:middle L:90%
build. And we want to use this as a

934
00:55:10.150 --> 00:55:14.880 A:middle L:90%
continuing guide for this um privacy project that we have

935
00:55:14.880 --> 00:55:17.260 A:middle L:90%
that deals with a community oriented perspective on privacy.

936
00:55:19.139 --> 00:55:22.980 A:middle L:90%
So these are the various people who have collaborated in

937
00:55:22.980 --> 00:55:25.309 A:middle L:90%
this larger project. So Denis Grachev and in his

938
00:55:25.320 --> 00:55:28.639 A:middle L:90%
mug shot here, he didn't give me a better

939
00:55:28.639 --> 00:55:31.289 A:middle L:90%
one. So uh is really the collaborator that I've

940
00:55:31.289 --> 00:55:35.769 A:middle L:90%
been working with on this um on this information flow

941
00:55:35.769 --> 00:55:39.219 A:middle L:90%
control meta model. Um but other faculty and and

942
00:55:39.219 --> 00:55:45.900 A:middle L:90%
other students have worked on other parts of this bigger

943
00:55:45.900 --> 00:55:49.159 A:middle L:90%
project, which is about privacy in a community setting

944
00:55:49.539 --> 00:55:54.809 A:middle L:90%
. Where um so the way in which we came

945
00:55:54.809 --> 00:55:59.389 A:middle L:90%
to to define this meta model was because we had

946
00:55:59.389 --> 00:56:04.340 A:middle L:90%
a proposal about studying community privacy where the reviewers kept

947
00:56:04.730 --> 00:56:07.610 A:middle L:90%
saying why isn't this just access control? So he

948
00:56:07.610 --> 00:56:10.650 A:middle L:90%
said fine, I'll tell you why it's not because

949
00:56:10.650 --> 00:56:14.639 A:middle L:90%
we're going to develop this freaking model and that's what

950
00:56:14.639 --> 00:56:19.699 A:middle L:90%
we're doing and you see it's really not that Okay

951
00:56:19.710 --> 00:56:22.440 A:middle L:90%
, so this is the time for questions, the

952
00:56:22.440 --> 00:56:25.679 A:middle L:90%
most important of which is where is the sign up

953
00:56:25.679 --> 00:56:31.789 A:middle L:90%
sheet? Where is it? Okay, so there

954
00:56:31.789 --> 00:56:34.949 A:middle L:90%
it is? Alright, so I've answered that question

955
00:56:34.949 --> 00:56:36.489 A:middle L:90%
for you, are there other questions that I can

956
00:56:36.489 --> 00:56:38.530 A:middle L:90%
answer for you? First of all I should say

957
00:56:38.530 --> 00:56:43.949 A:middle L:90%
in my part. Thanks for coming. The last

958
00:56:44.530 --> 00:56:46.449 A:middle L:90%
, the way you define friendship is in two ways

959
00:56:46.619 --> 00:56:52.090 A:middle L:90%
. One is if you agree fourth to give the

960
00:56:52.090 --> 00:56:54.750 A:middle L:90%
last seminar of the year for someone you're their friend

961
00:56:55.730 --> 00:56:59.210 A:middle L:90%
and if you come to the last seminar of the

962
00:56:59.210 --> 00:57:01.599 A:middle L:90%
year, you're my friend. Alright, so thank

963
00:57:01.599 --> 00:57:04.340 A:middle L:90%
you very much, I applaud you for coming.

964
00:57:08.530 --> 00:57:10.719 A:middle L:90%
So are there questions or do we want to just

965
00:57:10.730 --> 00:57:34.969 A:middle L:90%
go to lunch? Yeah. Right. I'll get

966
00:57:34.969 --> 00:57:37.300 A:middle L:90%
a better sense of this later in the summer.

967
00:57:37.300 --> 00:57:39.980 A:middle L:90%
But um it certainly hasn't stopped people from defining new

968
00:57:39.980 --> 00:57:45.639 A:middle L:90%
models. Um but at least it may cause them

969
00:57:45.929 --> 00:57:50.019 A:middle L:90%
to at least have to write that paragraph that says

970
00:57:50.630 --> 00:57:52.460 A:middle L:90%
why are we defining yet a different model? And

971
00:57:52.460 --> 00:57:55.360 A:middle L:90%
how does it relate to other models? It's just

972
00:57:55.360 --> 00:57:59.059 A:middle L:90%
like Landon's paper didn't stop people from inventing new programming

973
00:57:59.059 --> 00:58:07.800 A:middle L:90%
languages, other questions, thoughts remember as always there'll

974
00:58:07.800 --> 00:58:09.230 A:middle L:90%
be an opportunity for the meet the speaker later today

975
00:58:09.230 --> 00:58:12.920 A:middle L:90%
, out in Knowledge Works. Uh In fact,

976
00:58:12.920 --> 00:58:15.360 A:middle L:90%
we remember that there is the usual reception at Barbara's

977
00:58:15.360 --> 00:58:19.659 A:middle L:90%
house this evening. Thank you

