A Valid And Correct-By-Construction Formal Specification Of Rbac

INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY(2020)

引用 2|浏览9
暂无评分
摘要
Controlling access to data is one of the primary purposes of security, especially when it comes to dealing with safety critical systems. In such systems, it is of paramount importance to rigorously define access control models. In this article, a correct-by-construction specification of RBAC using the Event-B formal method is proposed. The specification defines closely the model properties with the behavior aspect of RBAC as guards of events, which allows applying a priori verifications. Accordingly, the resulted specification is correct-by-construction and avoids the combinatorial explosion problem. As well, a number of refinement operations are performed leading to a specification with several abstraction levels, where each level implements selected RBAC entities. The approach is illustrated by an instantiation of a healthcare system.
更多
查看译文
关键词
A Priori Verification, Correct-by-Construction, Event-B, Formal Methods, Proof and Refinement, Role-Based Access Control, Specification and Validation
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要