Applying SDL to formal analysis of security systems

  • Authors:
  • Javier López;Juan J. Ortega;José M. Troya

  • Affiliations:
  • Computer Science Department, E.T.S. Ingeniería Informática, University of Malaga, Malaga, Spain;Computer Science Department, E.T.S. Ingeniería Informática, University of Malaga, Malaga, Spain;Computer Science Department, E.T.S. Ingeniería Informática, University of Malaga, Malaga, Spain

  • Venue:
  • SDL'03 Proceedings of the 11th international conference on System design
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Nowadays, it is widely accepted that critical systems have to be formally analyzed to achieve well-known benefits of formal methods. To study the security of communication systems, we have developed a methodology for the application of the formal analysis techniques commonly used in communication protocols to the analysis of cryptographic ones. In particular, we have extended the design and analysis phases with security properties. Our proposal uses a specification notation based on MSC, which can be automatically translated into a generic SDL specification. This SDL system can then be used for the analysis of the desired security properties, by using an observer process schema. Apart from our main goal of providing a notation for describing the formal specification of security systems, our proposal also brings additional benefits, such as the study of the possible attacks to the system, and the possibility of reusing the specifications produced to describe and analyze more complex systems.