...
首页> 外文期刊>International Journal of Information Security >Using Hierarchical Timed Coloured Petri Nets in the formal study of TRBAC security policies
【24h】

Using Hierarchical Timed Coloured Petri Nets in the formal study of TRBAC security policies

机译:在TRBAC安全政策的正式研究中使用等级彩色培养网

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Role-Based Access Control (RBAC) is one of the most used models in designing and implementation of security policies, in large networking systems. Basic RBAC model does not consider temporal aspects which are so important in such policies. Temporal RBAC (TRBAC) is proposed to deal with these temporal aspects. Despite the elegance of these models, designing a security policy remains a challenge. Designers must ensure the consistency and the correctness of the policy. The use of formal methods provides techniques for proving that the designed policy is consistent. In this paper, we present a formal modelling/analysis approach of TRBAC policies. This approach uses Hierarchical Timed Coloured Petri Nets (HTCPN) formalism to model the TRBAC policy, and the CPN-tool to analyse the generated models. The timed aspect, in HTCPN, facilitates the consideration of temporal constraints introduced in TRBAC. The hierarchical aspect of HTCPN makes the model "manageable", in spite of the complexity of TRBAC policy specification. The analysis phase allows the verification of many important properties about the TRBAC security policy.
机译:基于角色的访问控制(RBAC)是在大型网络系统中设计和实施安全策略中最常用的模型之一。基本的RBAC模型不考虑在此类政策中非常重要的时间方面。建议临时RBAC(TRBAC)来处理这些时间方面。尽管这些模型的优雅,设计安全政策仍然是一个挑战。设计人员必须确保一致性和政策的正确性。使用形式方法提供了证明所设计的政策一致的技术。在本文中,我们展示了TRBAC政策的正式建模/分析方法。这种方法使用分层定时彩色Petri网(HTCPN)形式主义来模拟TRBAC策略,以及分析所生成的模型的CPN-Tool。在HTCPN中的定时方面有助于考虑TRBAC中引入的时间限制。尽管TBAC策略规范的复杂性,HTCPN的分层方面使模型“可管理”。分析阶段允许验证TRBAC安全政策的许多重要属性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号