A case study in decentralized, dynamic, policy-based, authorization and trust management: automated software distribution for airplanes

  • Authors:
  • Peter Hartmann;Monika Maidl;David Von Oheimb;Richard Robinson

  • Affiliations:
  • Landshut University of Appl. Sciences, Landshut, Germany;Siemens Corporate Technology, München, Germany;Siemens Corporate Technology, München, Germany;Boeing Research & Technology, Seattle, WA

  • Venue:
  • STM'10 Proceedings of the 6th international conference on Security and trust management
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We apply SecPAL, a logic-based policy language for decentralized authorization and trust management, to our case study of automated software distribution for airplanes. In contrast to established policy frameworks for authorization like XACML, SecPAL offers constructs to express trust relationships and delegation explicitly and to form chains of trusts. We use these constructs in our case study to specify and reason about dynamic, ad-hoc trust relationships between airlines and contractors of suppliers of software that has to be loaded into airplanes.