Abstract: We investigate the logical foundations of hyperproperties. Hyperproperties generalize trace properties, which are sets of traces, to sets of sets of traces. The most prominent application of hyperproperties is information flow security: information flow policies characterize the secrecy and integrity of a system by comparing two or more execution traces, for example by comparing the observations made by an external observer on execution traces that result from different values of a secret variable. In this paper, we establish the first connection between temporal logics for hyperproperties and first-order logic. Kamp's seminal theorem (in the formulation due to Gabbay et al.) states that linear-time temporal logic (LTL) is expressively equivalent to first-order logic over the natural numbers with order. We introduce first-order logic over sets of traces and prove that HyperLTL, the extension of LTL to hyperproperties, is strictly subsumed by this logic. We furthermore exhibit a fragment that is expressively equivalent to HyperLTL, thereby establishing Kamp's theorem for hyperproperties.
Recommendations
Cited in
(26)- Team semantics for the specification and verification of hyperproperties
- A temporal logic for asynchronous hyperproperties
- HyperATL*: A Logic for Hyperproperties in Multi-Agent Systems
- Model checking algorithms for hyperproperties (invited paper)
- Temporal hyperproperties
- Compositional model checking for multi-properties
- Good-for-Game QPTL: An Alternating Hodges Semantics
- Unifying hyper and epistemic temporal logics
- Explaining Hyperproperty Violations
- HyperLTL satisfiability is highly undecidable, \(\mathrm{HyperCTL}^*\) is even harder
- On the expressive power of TeamLTL and first-order team logic over hyperproperties
- On the complexity of linear temporal logic with team semantics
- The complexity of second-order HyperLTL
- Synthesis from hyperproperties
- A remark on the expressivity of asynchronous TeamLTL and HyperLTL
- Flavors of sequential information flow
- Centralized vs. decentralized monitors for hyperproperties
- Deciding hyperproperties combined with functional specifications
- Temporal team semantics revisited
- The complexity of second-order HyperLTL
- Realizable and context-free hyperlanguages
- The hierarchy of hyperlogics
- Unifying asynchronous logics for hyperproperties
- Expressivity of asynchronous TeamLTL and HyperLTL
- Explainability requirements as hyperproperties
- Second-order hyperproperties
This page was built for publication: The first-order logic of hyperproperties
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q4636628)