TU Darmstadt / ULB / TUbiblio

From Formal Access Control Policies to Runtime Enforcement Aspects

Kallel, Slim ; Charfi, Anis ; Mezini, Mira ; Jmaiel, Mohamed ; Klose, Karl (2009)
From Formal Access Control Policies to Runtime Enforcement Aspects.
In: Proceedings of the 1st International Symposium on Engineering Secure Software and Systems
doi: 10.1007/978-3-642-00199-4_2
Buchkapitel, Bibliographie

Kurzbeschreibung (Abstract)

We present an approach that addresses both formal specification and verification as well as runtime enforcement of RBAC access control policies including application specific constraints such as separation of duties (SoD). We introduce Temporal Z, a formal language based on Z and temporal logic, which provides domain specific predicates for expressing RBAC and SoD constraints. An aspect-oriented language with domain specific concepts for RBAC and SoD constraints is used for the runtime enforcement of policies. Enforcement aspects are automatically generated from Temporal Z specifications hence avoiding the possibility of errors and inconsistencies that may be introduced when enforcement code is written manually. Furthermore, the use of aspects ensures the modularity of the enforcement code and its separation from the business logic.

Typ des Eintrags: Buchkapitel
Erschienen: 2009
Autor(en): Kallel, Slim ; Charfi, Anis ; Mezini, Mira ; Jmaiel, Mohamed ; Klose, Karl
Art des Eintrags: Bibliographie
Titel: From Formal Access Control Policies to Runtime Enforcement Aspects
Sprache: Englisch
Publikationsjahr: 2009
Ort: Berlin/Heidelberg, Germany
Buchtitel: Proceedings of the 1st International Symposium on Engineering Secure Software and Systems
Reihe: Lecture Notes In Computer Science
Band einer Reihe: 5429
Veranstaltungstitel: 1st International Symposium on Engineering Secure Software and Systems (ESSoS '09)
Veranstaltungsort: Leuven, Belgium
DOI: 10.1007/978-3-642-00199-4_2
Kurzbeschreibung (Abstract):

We present an approach that addresses both formal specification and verification as well as runtime enforcement of RBAC access control policies including application specific constraints such as separation of duties (SoD). We introduce Temporal Z, a formal language based on Z and temporal logic, which provides domain specific predicates for expressing RBAC and SoD constraints. An aspect-oriented language with domain specific concepts for RBAC and SoD constraints is used for the runtime enforcement of policies. Enforcement aspects are automatically generated from Temporal Z specifications hence avoiding the possibility of errors and inconsistencies that may be introduced when enforcement code is written manually. Furthermore, the use of aspects ensures the modularity of the enforcement code and its separation from the business logic.

Fachbereich(e)/-gebiet(e): 20 Fachbereich Informatik
20 Fachbereich Informatik > Softwaretechnik
Hinterlegungsdatum: 14 Sep 2009 07:16
Letzte Änderung: 03 Jun 2018 21:23
PPN:
Export:
Suche nach Titel in: TUfind oder in Google
Frage zum Eintrag Frage zum Eintrag

Optionen (nur für Redakteure)
Redaktionelle Details anzeigen Redaktionelle Details anzeigen