Towards Language-Theoretic Security for Dynamic Documents

No ratings

Presented at LangSec Workshop 2024 by

The computational capabilities of documents present an eternal challenge to security, in part because computation is often an afterthought in the design of document languages and formats. Our recent work is about providing language-theoretic foundations for reasoning about how computation affects a document (encapsulated in "document calculi"). These foundations suggest an intriguing question: if one were to carefully design a new document language from scratch, could it be made secure by construction based on these foundations? This talk explores some possibilities based on combining the document calculi with prior linguistic approaches such as object capabilities, language layers, and sandboxing. We will argue that these design elements might provably eliminate a wide variety of document security issues while still being able to express rich dynamic documents.