28605 articles – 22086 references  [version française]

inria-00525761, version 1

Specification, analysis and transformation of security policies via rewriting techniques

Tony Bourdier () 1

Journal of Information Assurance and Security 6, 5 (2011) 357-368

Abstract: Formal methods for the specification and analysis of security policies have drawn many attention recently. It is now well known that security policies can be represented using rewriting systems. These systems constitute an interesting formalism to prove properties while provides an operational way to evaluate authorization requests. In this paper, we propose to split the expression of security policies in two distinct elements: a security model and a configuration. The security model (expressed as an equational problem) describes how authorization requests must be evaluated depending on security information. The configuration (expressed as a rewriting system) assigns values to security information. This separation eases the formal analysis of security policies, and makes it possible to automatically convert a given policy to a new security model.

  • 1:  PAREO (INRIA Lorraine - LORIA)
  • INRIA – CNRS : UMR7503 – Université Henri Poincaré - Nancy I – Université Nancy II – Institut National Polytechnique de Lorraine (INPL)
  • Domain : Computer Science/Cryptography and Security
    Computer Science/Formal Languages and Automata Theory
    Computer Science/Logic in Computer Science
 
  • inria-00525761, version 1
  • oai:hal.inria.fr:inria-00525761
  • From: 
  • Submitted on: Thursday, 14 October 2010 13:05:35
  • Updated on: Thursday, 7 July 2011 10:22:17