Skip to main navigation Skip to search Skip to main content

A framework of composable access control definition, enforcement and assurance

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

This paper proposes an approach for secure software design and coding; and, it provides a formal underpinning for security assurance, i.e., a proof that the generated code correctly realizes security specifications. The base of the proposed approach is a set of security features [17] that separate security concerns from the main design. To create specific access control models, designers can select the features they require, compose them, and represent them through security diagrams [17], i.e., extensions to UML to represent security concerns. These security specifications are then transitioned into aspect-oriented enforcement code. To provide security assurance, this paper formalizes the application behavior using labeled transition systems and structural operational semantics; and it uses simulation relations to demonstrate the correctness of the secure code.

Original languageEnglish
Title of host publicationProceedings - International Conference of the Chilean Computer Science Society, SCCC 2008
Pages13-22
Number of pages10
DOIs
StatePublished - 2008
Externally publishedYes
Event27th International Conference of the Chilean Computer Science Society, SCCC 2008 - Punta Arenas, Chile
Duration: 10 Nov 200814 Nov 2008

Publication series

NameProceedings - International Conference of the Chilean Computer Science Society, SCCC
ISSN (Print)1522-4902

Conference

Conference27th International Conference of the Chilean Computer Science Society, SCCC 2008
Country/TerritoryChile
CityPunta Arenas
Period10/11/0814/11/08

Fingerprint

Dive into the research topics of 'A framework of composable access control definition, enforcement and assurance'. Together they form a unique fingerprint.

Cite this