首页> 外文会议>International conference on abstract state machines, alloy, B, TLA, VDM, and Z >Clarification of Ambiguity for the Simple Authentication and Security Layer
【24h】

Clarification of Ambiguity for the Simple Authentication and Security Layer

机译:澄清简单身份验证和安全层的歧义

获取原文

摘要

The Simple Authentication and Security Layer (SASL) is a framework for enabling application protocols to support authentication, integrity and confidentiality services. The SASL was originally specified in RFC 2222, and later updated in RFC 4422, using natural language. However, due to the richness of natural language this involves ambiguities and imprecision. Whilst there is an Oracle implementation of SASL, its documentation also contains informal descriptions and under-defined specifications of the RFCs. This paper provides clarification of ambiguity in SASL using Abstract State Machines (ASMs). This clarification is based on two ASM essential notions: a ground model to capture the intended SASL behavior in an understandable way, and a refinement notion to accurately explicate the ambiguous parts of the behavior. We also show some differences between RFCs and the description of the Oracle implementation. We believe our work can serve as a basis for further implementation and for formal analysis.
机译:简单身份验证和安全层(SASL)是一个框架,用于使应用程序协议支持身份验证,完整性和机密性服务。 SASL最初是在RFC 2222中指定的,后来使用自然语言在RFC 4422中进行了更新。但是,由于自然语言的丰富性,这会导致模棱两可和不精确。尽管有Oracle的SASL实现,但其文档也包含RFC的非正式描述和定义不足的规范。本文澄清了使用抽象状态机(ASM)的SASL中的歧义。此澄清基于两个ASM基本概念:一个以可理解的方式捕获预期的SASL行为的基础模型,以及一个精确定义行为歧义部分的细化概念。我们还展示了RFC与Oracle实现描述之间的一些差异。我们相信我们的工作可以作为进一步实施和正式分析的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号