A framework of composable access control definition, enforcement and assurance

Jaime A. Pavlich-Mariscal, Steven A. Demurjian, Laurent D. Michel

Producción: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

5 Citas (Scopus)

Resumen

This paper proposes an approach for secure software design and coding; and, it provides a formal underpinning for security assurance, i.e., a proof that the generated code correctly realizes security specifications. The base of the proposed approach is a set of security features [17] that separate security concerns from the main design. To create specific access control models, designers can select the features they require, compose them, and represent them through security diagrams [17], i.e., extensions to UML to represent security concerns. These security specifications are then transitioned into aspect-oriented enforcement code. To provide security assurance, this paper formalizes the application behavior using labeled transition systems and structural operational semantics; and it uses simulation relations to demonstrate the correctness of the secure code.

Idioma originalInglés
Título de la publicación alojadaProceedings - International Conference of the Chilean Computer Science Society, SCCC 2008
Páginas13-22
Número de páginas10
DOI
EstadoPublicada - 2008
Publicado de forma externa
Evento27th International Conference of the Chilean Computer Science Society, SCCC 2008 - Punta Arenas, Chile
Duración: 10 nov. 200814 nov. 2008

Serie de la publicación

NombreProceedings - International Conference of the Chilean Computer Science Society, SCCC
ISSN (versión impresa)1522-4902

Conferencia

Conferencia27th International Conference of the Chilean Computer Science Society, SCCC 2008
País/TerritorioChile
CiudadPunta Arenas
Período10/11/0814/11/08

Huella

Profundice en los temas de investigación de 'A framework of composable access control definition, enforcement and assurance'. En conjunto forman una huella única.

Citar esto