Enabling verification and conformance testing for access control model

  • Authors:
  • Hongxin Hu;GailJoon Ahn

  • Affiliations:
  • The University of North Carolina at Charlotte;The University of North Carolina at Charlotte

  • Venue:
  • Proceedings of the 13th ACM symposium on Access control models and technologies
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Verification and testing are the important step for software assurance. However, such crucial and yet challenging tasks have not been widely adopted in building access control systems. In this paper we propose a methodology to support automatic analysis and conformance testing for access control systems, integrating those features to Assurance Management Framework (AMF). Our methodology attempts to verify formal specifications of a role-based access control model and corresponding policies with selected security properties. Also, we systematically articulate testing cases from formal specifications and validate conformance to the system design and implementation using those cases. In addition, we demonstrate feasibility and effectiveness of our methodology using SAT and Alloy toolset.