首页> 外文期刊>Journal of symbolic computation >Intruder deducibility constraints with negation. Decidability and application to secured service compositions
【24h】

Intruder deducibility constraints with negation. Decidability and application to secured service compositions

机译:否定性限制了入侵者的演绎性。可确定性及其在担保服务组合中的应用

获取原文
获取原文并翻译 | 示例
           

摘要

We consider a problem of automated orchestration of security aware services under additional constraints. The problem of finding a mediator to compose secured services has been reduced in previous works to the problem of solving deducibility constraints similar to those employed for cryptographic protocol analysis. We extend in this paper the mediator synthesis procedure (i.e. a solution for the orchestration problem) by allowing additional non-disclosure policies that express the fact that some data is not accessible to the mediator at a given point of its execution. We present a decision procedure that answers the question whether a mediator satisfying these policies can be effectively synthesized. The approach presented in this work extends the constraint solving procedure for cryptographic protocol analysis in a significant way as to be able to handle negation of deducibility constraints. It applies to all subterm convergent theories and therefore covers several interesting theories in formal security analysis including encryption, hashing, signature and pairing; it is also expressive enough for some RBAC policies. A variant of this procedure for Dolev Yao theory has been implemented in CI-Atse, a protocol analysis tool based on constraint solving. (C) 2016 Elsevier Ltd. All rights reserved.
机译:我们考虑在附加约束下自动协调安全意识服务的问题。在以前的工作中,寻找调解人来组成安全服务的问题已经减少到了解决类似于密码协议分析所采用的推论约束的问题。我们在本文中扩展了介体综合过程(即编排问题的解决方案),方法是允许附加的非公开策略表示某些数据在介体执行的给定点不可访问的事实。我们提出了一个决策程序,该程序回答了能否有效地合成满足这些政策的调解人的问题。这项工作中提出的方法以一种重要的方式扩展了用于密码协议分析的约束解决程序,以便能够处理可推导性约束的否定。它适用于所有子项收敛理论,因此涵盖了正式安全分析中的一些有趣理论,包括加密,哈希,签名和配对。对于某些RBAC政策,它也具有足够的表现力。 Dolev Yao理论的此过程的变体已在CI-Atse中实现,CI-Atse是一种基于约束求解的协议分析工具。 (C)2016 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号