Chapter

Formal Techniques for Networked and Distributed Systems - FORTE 2006

Volume 4229 of the series Lecture Notes in Computer Science pp 99-114

Formal Analysis of Dynamic, Distributed File-System Access Controls

  • Avik ChaudhuriAffiliated withComputer Science Department, University of California
  • , Martín AbadiAffiliated withComputer Science Department, University of CaliforniaMicrosoft Research

Abstract

We model networked storage systems with distributed, cryptographically enforced file-access control in an applied pi calculus. The calculus contains cryptographic primitives and supports file-system constructs, including access revocation. We establish that the networked storage systems implement simpler, centralized storage specifications with local access-control checks. More specifically, we prove that the former systems preserve safety properties of the latter systems. Focusing on security, we then derive strong secrecy and integrity guarantees for the networked storage systems.