What is a secret—and—what does that have to do with computer security?
Ruth Nelson
Abstract
Ruth Nelson
Abstract
This paper questions some of the basic assumptions of computer security in the context of keeping secrets, and it finds some major discrepancies. It then proposes a new paradigm for functional security in computer systems.The first conclusion of the paper is that secrecy and security cannot be expressed both algorithmically and accurately. The second conclusion of the paper is that functional security models, which look at the application software as well as the data, can be very useful. Use of more realistic models involves a more complex definition of secure systems, but it may reduce the conflict between security and function and may result in more effective secure systems.
OpenAlex reports 10 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper questions some of the basic assumptions of computer security in the context of keeping secrets, and it finds some major discrepancies. It then proposes a new paradigm for functional security in computer systems.The first conclusion of the paper is that secrecy and security cannot be expressed both algorithmically and accurately. The second conclusion of the paper is that functional security models, which look at the application software as well as the data, can be very useful. Use of more realistic models involves a more complex definition of secure systems, but it may reduce the conflict between security and function and may result in more effective secure systems.
Key concepts: Computer science, Secrecy, Computer security model, Computer security, Context (archaeology), Software security assurance, Security through obscurity, Cloud computing security