Synthesising verified access control systems in XACML

  • Authors:
  • Nan Zhang;Mark Ryan;Dimitar P. Guelev

  • Affiliations:
  • University of Birmingham, Birmingham, UK;University of Birmingham, Birmingham, UK;University of Birmingham, Birmingham, UK

  • Venue:
  • Proceedings of the 2004 ACM workshop on Formal methods in security engineering
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

The eXtensible Access Control Markup Language (XACML) was proposed by the OASIS committee to be used as a standard language in e-business [6]. However, policy files written in XACML are hard to read and analyse directly. In this paper, we present a tool which generates verified XACML scripts from access control system descriptions in simple but expressive language proposed in [3], which admits algorithmic verification of access control systems against appropriately formalised policies. This allows the generation of XACML scripts for systems that can be formally verified to be implementing the relevant policies.