Protection Monotonicity and Canonical Selector Algebra for Auditable State Machines

Stateful control systems often enforce permissions, prohibitions, revocations, and exceptions over structured request domains. The difficult failures occur not when a policy is obviously removed, but when protection is weakened indirectly through restoration, supersession, partial replacement, lineage changes, policy updates, or future transition types whose implementations do not explicitly reason about earlier restrictions. This paper develops a kernel-wide protection monotonicity framework for auditable state machines. Protection is represented as a function over a canonical request domain rather than as a collection of policy objects. Ordinary transitions are required to preserve or strengthen effective protection at every request point. Any decrease must occur through a separately typed and specifically authorized relaxation operation.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23068654
Primary Topic
Security and Verification in Computing
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Protection Monotonicity and Canonical Selector Algebra for Auditable State Machines

E. M. Honeycutt III
Zenodo (CERN European Organization for Nuclear Research)
Security and Verification in Computing
preprint

Protection Monotonicity and Canonical Selector Algebra for Auditable State Machines

E. M. Honeycutt III
preprint en

Abstract

Stateful control systems often enforce permissions, prohibitions, revocations, and exceptions over structured request domains. The difficult failures occur not when a policy is obviously removed, but when protection is weakened indirectly through restoration, supersession, partial replacement, lineage changes, policy updates, or future transition types whose implementations do not explicitly reason about earlier restrictions. This paper develops a kernel-wide protection monotonicity framework for auditable state machines. Protection is represented as a function over a canonical request domain rather than as a collection of policy objects. Ordinary transitions are required to preserve or strengthen effective protection at every request point. Any decrease must occur through a separately typed and specifically authorized relaxation operation.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Protection Monotonicity and Canonical Selector Algebra for Auditable State Machines — E. M. Honeycutt III · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS