...
首页> 外文期刊>Electronic Communications of the EASST >Verifying Access Control in Statecharts
【24h】

Verifying Access Control in Statecharts

机译:验证状态图中的访问控制

获取原文
           

摘要

Access control is one of the main security mechanisms for software applications. It ensures that all accesses conform to a predefined access control policy. It is important to check that the access control policy is well implemented in the system. When following an MDD methodology it may be necessary to check this early during the development lifecycle, namely when modeling the application. This paper tackles the issue of verifying access control policies in statecharts. The approach is based on the transformation of a statechart into an Algebraic Petri net to enable checking access control policies and identifying potential inconsistencies with an OrBAC set of access control policies. Our method allows locating the part of the statechart that is causing the problem. The approach has been successfully applied to a Library Management System. Based on our proposal a tool for performing the transformation and localization of errors in the statechart has been implemented.
机译:访问控制是软件应用程序的主要安全机制之一。它确保所有访问都符合预定义的访问控制策略。重要的是要检查访问控制策略在系统中是否正确实施。在遵循MDD方法论时,可能有必要在开发生命周期的早期进行检查,即在对应用程序进行建模时。本文解决了验证状态图中的访问控制策略的问题。该方法基于状态图到代数Petri网的转换,以检查访问控制策略并识别与OrBAC访问控制策略集的潜在不一致。我们的方法允许定位导致问题的状态图的一部分。该方法已成功应用于图书馆管理系统。根据我们的建议,已实现了一种用于在状态图中执行错误的转换和定位的工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号