Alloy Community

User login

Enabling Verification and Conformance Testing for Access Control Model

Authors: 
Hongxin Hu and Gail-Joon Ahn
Publication Venue: 
In Proceedings of 13th ACM Symposium on Access Control Models And Technologies (SACMAT), Estes Park, Colorado, USA
When Published: 
Jun 11 2008

Veri¯cation and testing are the important step for software
assurance. However, such crucial and yet challenging tasks
have not been widely adopted in building access control sys-
tems. In this paper we propose a methodology to sup-
port automatic analysis and conformance testing for ac-
cess control systems, integrating those features to Assur-
ance Management Framework (AMF). Our methodology at-
tempts to verify formal speci¯cations of a role-based access
control model and corresponding policies with selected se-
curity properties. Also, we systematically articulate testing
cases from formal speci¯cations and validate conformance
to the system design and implementation using those cases.
In addition, we demonstrate feasibility and e®ectiveness of
our methodology using SAT and Alloy toolset.



Attachment


Size
sacmat08.pdf305.36 KB

Syndicate content  

The development of this site is supported by the National Science Foundation under Computing Research Infrastructure Grant No. 0707612.

Theme originally designed by Chris Herberte