An Access Control Model Based Testing Approach for Smart Card Applications: Results of the POSÉ Project

Abstract : This paper is about generating security tests from the Common Criteria expression of a security policy, in addition to functional tests previously generated by a model-based testing approach. The method that we present re-uses the functional model and the concretization layer developed for the functional testing, and relies on an additional security policy model. We discuss how to produce the security policy model from a Common Criteria security target. We propose to compute the tests by using some test purposes as guides for the tests to be extracted from the models. We see a test purpose as the combination of a security property and a test need issued from the know-how of a security engineer. We propose a language based on regular expressions for the expression of such test purposes. We illustrate our approach by means of the IAS1 case study, a smart card application dedicated to the operations of Identification, Authentication and electronic Signature.
Type de document :
Article dans une revue
Journal of Information Assurance and Security, Dynamic Publishers Inc., USA, 2010, 5 (1), pp.335-351. 〈http://www.mirlabs.org/jias/secured/Volume5-Issue1/Masson.pdf〉
Liste complète des métadonnées

https://hal.inria.fr/inria-00533220
Contributeur : Fabrice Bouquet <>
Soumis le : vendredi 5 novembre 2010 - 14:58:23
Dernière modification le : jeudi 11 octobre 2018 - 08:48:02

Identifiants

  • HAL Id : inria-00533220, version 1

Citation

Pierre-Alain Masson, Marie-Laure Potet, Jacques Julliand, Régis Tissot, Bruno Legeard, et al.. An Access Control Model Based Testing Approach for Smart Card Applications: Results of the POSÉ Project. Journal of Information Assurance and Security, Dynamic Publishers Inc., USA, 2010, 5 (1), pp.335-351. 〈http://www.mirlabs.org/jias/secured/Volume5-Issue1/Masson.pdf〉. 〈inria-00533220〉

Partager

Métriques

Consultations de la notice

613