|
|
Specification and Refinement of Access Control
|
|
|
|
|
نویسنده
|
Méry Dominique ,Merz Stephan
|
منبع
|
journal of universal computer science - 2007 - دوره : 13 - شماره : 8 - صفحه:1073 -1093
|
چکیده
|
Abstract: we consider the extension of fair event system specifications by concepts of access control (prohibitions, user rights, and obligations). we give proof rules for veri- fying that an access control policy is correctly implemented in a system, and consider preservation of access control by refinement of event systems. prohibitions and obliga- tions are expressed as properties of traces and are preserved by standard refinement notions of event systems. preservation of user rights is not guaranteed by construction; we propose to combine implementation-level user rights and obligations to implement high-level user rights.
|
کلیدواژه
|
access control ,event systems ,refinement
|
آدرس
|
Nancy University & LORIA, France, INRIA Nancy & LORIA, France
|
پست الکترونیکی
|
stephan.merz@loria.fr
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|