inria-00507300, version 2
Formal Specification and Validation of Security Policies
Tony Bourdier
1Horatiu Cirstea
1Mathieu Jaume 2Hélène Kirchner
a, 1, 3
FPS - 4th Canada-France MITACS Workshop on Foundations and Practice of Security - 2011 6888 (2011) 148-163
Résumé : We propose a formal framework for the specification and validation of security policies. To model a secured system, the evolution of security information in the system is described by transitions triggered by authorization requests and the policy is given by a set of rules describing the way the corresponding decisions are taken. Policy rules are constrained rewrite rules whose constraints are first-order formulas on finite domains, which provides enhanced expressive power compared to classical security policy specification approaches like the ones using Datalog, for example. Our specifications have an operational semantics based on transition and rewriting systems and are thus executable. This framework also provides a common formalism to define, compare and compose security systems and policies. We define transformations over secured systems in order to perform validation of classical security properties.
- a – CNRS
- 1 : PAREO (INRIA Lorraine - LORIA)
- INRIA – CNRS : UMR7503 – Université Henri Poincaré - Nancy I – Université Nancy II – Institut National Polytechnique de Lorraine (INPL)
- 2 : Laboratoire d'Informatique de Paris 6 (LIP6)
- CNRS : UMR7606 – Université Pierre et Marie Curie [UPMC] - Paris VI
- 3 : INRIA Bordeaux - Sud-Ouest (INRIA Bordeaux - Sud-Ouest)
- INRIA
- Domaine : Informatique/Cryptographie et sécurité
Informatique/Théorie et langage formel - Mots-clés : Security policies – formal specification – formal validation – constrained rewriting systems
- Versions disponibles : v1 (30-07-2010) v2 (23-02-2011)
- inria-00507300, version 2
- http://hal.inria.fr/inria-00507300
- oai:hal.inria.fr:inria-00507300
- Contributeur : Tony Bourdier
- Soumis le : Mardi 22 Février 2011, 09:01:02
- Dernière modification le : Lundi 7 Janvier 2013, 17:16:43






Documents associés
Exporter