首页> 外文会议>Software engineering and formal methods >On Run-Time Enforcement of Authorization Constraints in Security-Sensitive Workflows
【24h】

On Run-Time Enforcement of Authorization Constraints in Security-Sensitive Workflows

机译:安全敏感工作流中的授权约束的运行时强制

获取原文
获取原文并翻译 | 示例

摘要

In previous work, we showed how to use an SMT-based model checker to synthesize run-time enforcement mechanisms for business processes augmented with access control policies and authorization constraints, such as Separation of Duties. The synthesized enforcement mechanisms are able to guarantee both termination and compliance to security requirements, i.e. solving the run-time version of the Workflow Satisfiability Problem (WSP). No systematic approach to specify the various constraints considered in the WSP literature has been provided. In this paper, we first propose a classification of these constraints and then show how to encode them in the declarative input language of the SMT-based model checker used for synthesis. This shows the flexibility of the SMT approach to solve the run-time version of the WSP in presence of different authorization constraints.
机译:在先前的工作中,我们展示了如何使用基于SMT的模型检查器来为业务流程综合运行时强制机制,并增强了访问控制策略和授权约束(例如职责分离)。综合的执行机制能够保证终止并满足安全要求,即解决工作流可满足性问题(WSP)的运行时版本。没有提供系统的方法来指定WSP文献中考虑的各种约束。在本文中,我们首先提出这些约束的分类,然后展示如何在用于合成的基于SMT的模型检查器的声明性输入语言中对其进行编码。这显示了SMT方法在存在不同授权约束的情况下解决WSP的运行时版本的灵活性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号