【24h】

Modelling and Verification of Layered Security Protocols: A Bank Application

机译:分层安全协议的建模和验证:银行应用程序

获取原文
获取原文并翻译 | 示例

摘要

Designing security-critical systems correctly is very difficult and there are many examples of weaknesses arising in practice. A particular challenge lies in the development of layered security protocols motivated by the need to combine existing or specifically designed protocols that each enforce a particular security requirement. Although appealing from a practical point of view, this approach raises the difficult question of the security properties guaranteed by the combined layered protocols, as opposed to each protocol in isolation. In this work, we apply a method for facilitating the development of trustworthy security-critical systems using the computer-aided systems engineering tool AuToFocus to the particular problem of layered security protocols. We explain our method at the example of a banking application which is currently under development by a major German bank and is about to be put to commercial use.
机译:正确设计对安全至关重要的系统非常困难,并且在实践中存在许多弱点的示例。一个特殊的挑战在于分层安全协议的开发,这是由于需要结合各自执行特定安全要求的现有或专门设计的协议而引起的。尽管从实用的角度来看很有吸引力,但是这种方法提出了一个难题,即与单独的每个协议相反,组合的分层协议可以保证安全性。在这项工作中,我们将一种使用计算机辅助系统工程工具AuToFocus来促进可信赖的安全关键系统开发的方法应用于分层安全协议的特定问题。我们以一家大型德国银行目前正在开发并将要投入商业使用的银行应用为例来说明我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号