Towards a formal specification of access control - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2006

Towards a formal specification of access control

Mathieu Jaume
  • Fonction : Auteur
  • PersonId : 901267
Charles Morisset
  • Fonction : Auteur
  • PersonId : 969938

Résumé

Access control software must be based on a security policy model as software flaws often come from a lack of precision or some incoherences in the policy model. In this paper, we introduce an abstract framework allowing to define access control policies, in a very concise way, offering to refine specifications through several levels and ending by different possible implementations. Such a framework allows to formally reason about security policies and also to compare them, a point which is rarely approached. As an illustration, we give a formal description of the Bell and LaPadula and the Chinese Wall policies and we briefly sketch how to compare these two policies.
Fichier non déposé

Dates et versions

hal-01352113 , version 1 (05-08-2016)

Identifiants

  • HAL Id : hal-01352113 , version 1

Citer

Mathieu Jaume, Charles Morisset. Towards a formal specification of access control. Workshop on Foundations of Computer Security and Automated Reasoning for Security Protocol Analysis (FCS-ARSPA'06), Aug 2006, Seattle, Washington, United States. ⟨hal-01352113⟩
82 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More