Formal Development of a Secure Access Control Filter

Amel Mammar, Thi Mai Nguyen, Régine Laleau

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

With the advent of the internet, most organizations offer more and more access to their information systems in order to increase their benefits. However, such an opening may cause security issues if sufficient precautions are not taken. An adequate solution to secure access to information systems consists in (1) defining the sufficient security policies and (2) ensuring their correct deployment on a given technological infrastructure. The present paper deals with the first point by introducing a formal approach that permits to develop a secure filter for an information system that respects different kinds of security rules: functional, static and dynamic rules. The proposed approach uses the SecureUML language to express the static rules and adapts the UML activity diagrams for dynamic ones while the structure of the manipulated data and the functionalities are expressed using a UML class diagram. Starting from these graphical notations, the approach consists in mapping them into a B formal specification to ensure their consistency and validate the system. Finally, a proved filter, which permits to take into account different security rules, is formally derived using the B refinement technique.

Original languageEnglish
Title of host publicationProceedings - 17th IEEE International Symposium on High Assurance Systems Engineering, HASE 2016
EditorsRadu Babiceanu, Helene Waeselynck, Jie Xu, Raymond A. Paul, Bojan Cukic
PublisherIEEE Computer Society
Pages173-180
Number of pages8
ISBN (Electronic)9781467399128
DOIs
Publication statusPublished - 1 Mar 2016
Externally publishedYes
Event17th IEEE International Symposium on High Assurance Systems Engineering, HASE 2016 - Orlando, United States
Duration: 7 Jan 20169 Jan 2016

Publication series

NameProceedings of IEEE International Symposium on High Assurance Systems Engineering
Volume2016-March
ISSN (Print)1530-2059

Conference

Conference17th IEEE International Symposium on High Assurance Systems Engineering, HASE 2016
Country/TerritoryUnited States
CityOrlando
Period7/01/169/01/16

Keywords

  • Formal Method
  • Information Systems
  • Secure Filter
  • Verification

Fingerprint

Dive into the research topics of 'Formal Development of a Secure Access Control Filter'. Together they form a unique fingerprint.

Cite this