Protection Monotonicity and Canonical Selector Algebra for Auditable State Machines
Stateful control systems often enforce permissions, prohibitions, revocations, and exceptions over structured request domains. The difficult failures occur not when a policy is obviously removed, but when protection is weakened indirectly through restoration, supersession, partial replacement, lineage changes, policy updates, or future transition types whose implementations do not explicitly reason about earlier restrictions. This paper develops a kernel-wide protection monotonicity framework for auditable state machines. Protection is represented as a function over a canonical request domain rather than as a collection of policy objects. Ordinary transitions are required to preserve or strengthen effective protection at every request point. Any decrease must occur through a separately typed and specifically authorized relaxation operation.
Authors
- E. M. Honeycutt III
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-30
- DOI
- https://doi.org/10.5281/zenodo.23068654
- Primary Topic
- Security and Verification in Computing
- Type
- preprint