针对应用程序特定使用控制的端到端正确性验证方法

P. Rajkumar, Saswati Ghosh, P. Dasgupta
{"title":"针对应用程序特定使用控制的端到端正确性验证方法","authors":"P. Rajkumar, Saswati Ghosh, P. Dasgupta","doi":"10.1109/ICIINFS.2009.5429902","DOIUrl":null,"url":null,"abstract":"Usage control is a comprehensive access control model developed to cater the security needs of the wide range of application domains. Safety property of the usage control model ensures only the design level safety whereas the correctness of usage control in software application depends on the correctness of implementation as well. Most of the research in access control left the correctness of implementation as a general software verification problem. Software verification in general requires an extensive exploration of the complete state space, whereas access control of an application evolves over few repeated protection states. This paper presents a method to verify the correctness of usage control implementation by capturing and analyzing only the protection states. We use this method in the end to end correctness verification approach, which ensures the design as well as implementation correctness of usage control and we also provide an illustrative case study.","PeriodicalId":117199,"journal":{"name":"2009 International Conference on Industrial and Information Systems (ICIIS)","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"An end to end correctness verification approach for application specific usage control\",\"authors\":\"P. Rajkumar, Saswati Ghosh, P. Dasgupta\",\"doi\":\"10.1109/ICIINFS.2009.5429902\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Usage control is a comprehensive access control model developed to cater the security needs of the wide range of application domains. Safety property of the usage control model ensures only the design level safety whereas the correctness of usage control in software application depends on the correctness of implementation as well. Most of the research in access control left the correctness of implementation as a general software verification problem. Software verification in general requires an extensive exploration of the complete state space, whereas access control of an application evolves over few repeated protection states. This paper presents a method to verify the correctness of usage control implementation by capturing and analyzing only the protection states. We use this method in the end to end correctness verification approach, which ensures the design as well as implementation correctness of usage control and we also provide an illustrative case study.\",\"PeriodicalId\":117199,\"journal\":{\"name\":\"2009 International Conference on Industrial and Information Systems (ICIIS)\",\"volume\":\"6 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2009-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2009 International Conference on Industrial and Information Systems (ICIIS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICIINFS.2009.5429902\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 International Conference on Industrial and Information Systems (ICIIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIINFS.2009.5429902","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

摘要

使用控制是为满足广泛应用领域的安全需求而开发的一种综合访问控制模型。使用控制模型的安全性只保证了设计层面的安全性,而软件应用中使用控制的正确性还取决于实现的正确性。大多数访问控制的研究都将实现的正确性作为一个通用的软件验证问题。软件验证通常需要对完整的状态空间进行广泛的探索,而应用程序的访问控制则在几个重复的保护状态上发展。本文提出了一种通过捕获和分析保护状态来验证使用控制实现正确性的方法。我们将此方法应用于端到端正确性验证方法中,保证了使用控制的设计和实现的正确性,并给出了一个说明性的案例研究。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An end to end correctness verification approach for application specific usage control
Usage control is a comprehensive access control model developed to cater the security needs of the wide range of application domains. Safety property of the usage control model ensures only the design level safety whereas the correctness of usage control in software application depends on the correctness of implementation as well. Most of the research in access control left the correctness of implementation as a general software verification problem. Software verification in general requires an extensive exploration of the complete state space, whereas access control of an application evolves over few repeated protection states. This paper presents a method to verify the correctness of usage control implementation by capturing and analyzing only the protection states. We use this method in the end to end correctness verification approach, which ensures the design as well as implementation correctness of usage control and we also provide an illustrative case study.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Resource-Allocating Codebook for patch-based face recognition HVDC transmission line for interconnecting power grids in India and Sri Lanka Case study of WSN as a replacement for SCADA An end to end correctness verification approach for application specific usage control An autonomous distributed vehicle-to-grid control of grid-connected electric vehicle
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1