ASLan++ - A Formal Security Specification Language for Distributed Systems

ASLan++ - A Formal Security Specification Language for Distributed Systems
复制标题

ASLan - 分布式系统的形式安全规范语言

DOI:
--
复制
发表时间:
2010
期刊:
Formal Methods for Components and Objects
影响因子:
--
通讯作者:
S. Mödersheim
S. Mödersheim
中科院分区:
--
文献类型:
--
作者:
David von Oheimb;S. Mödersheim

文献摘要

被引文献

相似文献

本文介绍了AVANTSSAR规范语言ASLan++。ASLan++的设计是为了在通信和应用程序级别上正式指定动态组合的安全敏感Web服务和面向服务的体系结构、其相关的安全策略以及其安全属性。 我们介绍了ASLan++的主要概念,在一个小的,但非常有指导意义的运行示例,抽象的公司内部网的情况下,其特点是非线性和相互依赖的工作流,在不同的抽象层次,包括显式的基于凭证的身份验证机制,动态访问控制策略,通信安全和相关的安全目标。这表明了语言的灵活性和表达能力,并且所得到的模型在逻辑上是足够的,而另一方面,它们对于那些不是正式方法专家的系统设计者来说是清晰可读和可行的。
This paper introduces ASLan++, the AVANTSSAR Specification Language. ASLan++ has been designed for formally specifying dynamically composed security-sensitive web services and service-oriented architectures, their associated security policies, as well as their security properties, at both communication and application level. We introduce the main concepts of ASLan++ at a small but very instructive running example, abstracted form a company intranet scenario, that features non-linear and inter-dependent workflows, communication security at different abstraction levels including an explicit credentials-based authentication mechanism, dynamic access control policies, and the related security goals. This demonstrates the flexibility and expressiveness of the language, and that the resulting models are logically adequate, while on the other hand they are clear to read and feasible to construct for system designers who are not experts in formal methods.