An Access Control Model Based Testing Approach for Smart Card Applications: Results of the {POSÉ} Project - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue JIAS, Journal of Information Assurance and Security Année : 2010

An Access Control Model Based Testing Approach for Smart Card Applications: Results of the {POSÉ} Project

Résumé

This paper is about generating security tests from the Common Criteria expression of a security policy, in addition to functional tests previously generated by a model-based testing approach. The method that we present re-uses the functional model and the concretization layer developed for the functional testing, and relies on an additional security policy model. We discuss how to produce the security policy model from a Common Criteria security target. We propose to compute the tests by using some test purposes as guides for the tests to be extracted from the models. We see a test purpose as the combination of a security property and a test need issued from the know-how of a security engineer. We propose a language based on regular expressions for the expression of such test purposes. We illustrate our approach by means of the IAS case study, a smart card application dedicated to the operations of Identification, Authentication and electronic Signature.
Fichier principal
Vignette du fichier
mpjt_10_oip.pdf (422.86 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00943158 , version 1 (07-02-2014)

Identifiants

  • HAL Id : hal-00943158 , version 1

Citer

Pierre-Alain Masson, Marie-Laure Potet, Jacques Julliand, Régis Tissot, Georges Debois, et al.. An Access Control Model Based Testing Approach for Smart Card Applications: Results of the {POSÉ} Project. JIAS, Journal of Information Assurance and Security, 2010, 5, pp.335 - 351. ⟨hal-00943158⟩
221 Consultations
86 Téléchargements

Partager

Gmail Facebook X LinkedIn More