Formal Specification and Validation of Security Policies - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

Formal Specification and Validation of Security Policies

Résumé

We propose a formal framework for the specification and validation of security policies. To model a secured system, the evolution of security information in the system is described by transitions triggered by authorization requests and the policy is given by a set of rules describing the way the corresponding decisions are taken. Policy rules are constrained rewrite rules whose constraints are first-order formulas on finite domains, which provides enhanced expressive power compared to classical security policy specification approaches like the ones using Datalog, for example. Our specifications have an operational semantics based on transition and rewriting systems and are thus executable. This framework also provides a common formalism to define, compare and compose security systems and policies. We define transformations over secured systems in order to perform validation of classical security properties.
Fichier principal
Vignette du fichier
FormalSpecificationandValidationofSecurityPolicies.pdf (150.17 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00507300 , version 1 (30-07-2010)
inria-00507300 , version 2 (22-02-2011)

Identifiants

Citer

Tony Bourdier, Horatiu Cirstea, Mathieu Jaume, Hélène Kirchner. Formal Specification and Validation of Security Policies. FPS - 4th Canada-France MITACS Workshop on Foundations and Practice of Security - 2011, May 2011, Paris, France. pp.148-163, ⟨10.1007/978-3-642-27901-0_12⟩. ⟨inria-00507300v2⟩
361 Consultations
482 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More