Modular verification of security properties in actor implementations

参与者实现中安全属性的模块化验证

基本信息

项目摘要

Security and, in particular, information ow properties refer to the behavior of multi-agent distributed systems. Typical examples are privacy aspects in social networks and confidentiality issues in online trading systems. Verification of such properties has to meet the following challenges:•Information ow properties are more complex than safety and liveness properties because they are defined in terms of sets of possible system traces.•The analysis has to take into account malicious agents that try to corrupt the system.•To scale, the verification has to be modular, i.e., the implementation of each (benevolent) agent should be separately analyzable.We will develop a tool-supported, two-tier framework for the verification of security properties in actor implementations of multi-agent systems. The specification tier supports modeling of systems as communicating agents and formalizing their security properties. It will be realized as a generic theory in a higher-order interactive proof assistant. Starting from the model and property definitions, the theory supports the decomposition of global properties into sufficient agent-local properties. The implementation tier assumes that agents are implemented as object-oriented programs following the actor paradigm. From the model, we will generate interface specifications for the actors and verify that the program code satisies these specifications. Thus, the project provides a tool-supported framework for bridging the gap between system-level security analysis and distributed implementations.
安全性,特别是信息和属性指的是多代理分布式系统的行为。典型的例子是社交网络中的隐私问题和在线交易系统中的保密问题。此类属性的验证必须满足以下挑战:·信息流属性比安全和活性属性更复杂,因为它们是根据可能的系统踪迹集定义的。·分析必须考虑试图破坏系统的恶意代理。·为了规模,验证必须是模块化的,即每个(仁慈的)代理的实现应该是可单独分析的。我们将开发一个工具支持的两层框架,用于验证多代理系统的参与者实现中的安全属性。规范层支持将系统建模为通信代理并形式化它们的安全属性。它将作为一个通用理论在一个更高阶的交互证明助手中实现。该理论从模型和属性定义出发,支持将全局属性分解为充分的代理局部属性。实现层假定代理被实现为遵循参与者范例的面向对象的程序。从模型中,我们将为参与者生成接口规范,并验证程序代码是否满足这些规范。因此,该项目提供了一个工具支持的框架,用于弥合系统级安全分析和分布式实施之间的差距。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Professor Dr. Arnd Poetzsch-Heffter其他文献

Professor Dr. Arnd Poetzsch-Heffter的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Professor Dr. Arnd Poetzsch-Heffter', 18)}}的其他基金

Semantische Kapselung und Nebenläufigkeitstransparenz in der objektorientierten Programmierung
面向对象编程中的语义封装和并发透明
  • 批准号:
    18162541
  • 财政年份:
    2005
  • 资助金额:
    --
  • 项目类别:
    Research Grants

相似海外基金

POSE: Phase II: Open-Source Precision, High Accuracy and Security Environment (OpenPHASE) For Time Verification, Calibration, and Interoperability
POSE:第二阶段:用于时间验证、校准和互操作性的开源精密、高精度和安全环境 (OpenPHASE)
  • 批准号:
    2303726
  • 财政年份:
    2023
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
Cyber Security, specifically trusted execution, more specifi cally remote verification of devices.
网络安全,特别是可信执行,更具体地说是设备的远程验证。
  • 批准号:
    2882995
  • 财政年份:
    2023
  • 资助金额:
    --
  • 项目类别:
    Studentship
SaTC: CORE: Small: Automating the End-to-End Verification of Security Protocol Implementations
SaTC:核心:小型:自动化安全协议实施的端到端验证
  • 批准号:
    2224279
  • 财政年份:
    2022
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
Commercialization Readiness Pilot (CRP) program support for: An Integrated Device for identification of bloodstream infections directly from blood
商业化准备试点 (CRP) 计划支持: 用于直接从血液中识别血流感染的集成设备
  • 批准号:
    10583448
  • 财政年份:
    2022
  • 资助金额:
    --
  • 项目类别:
REWIRE - REWiring the ComposItional Security VeRification and AssurancE of Systems of Systems Lifecycle
REWIRE - 重新构建系统生命周期的组合安全验证和保证
  • 批准号:
    10043730
  • 财政年份:
    2022
  • 资助金额:
    --
  • 项目类别:
    EU-Funded
Commercialization Readiness Pilot (CRP) program support for: An Integrated Device for identification of bloodstream infections directly from blood
商业化准备试点 (CRP) 计划支持: 用于直接从血液中识别血流感染的集成设备
  • 批准号:
    10318834
  • 财政年份:
    2022
  • 资助金额:
    --
  • 项目类别:
Verification of the effectiveness of a nursing practice record and guidance system using a highly functional security tool
使用功能强大的安全工具验证护理实践记录和指导系统的有效性
  • 批准号:
    21K17342
  • 财政年份:
    2021
  • 资助金额:
    --
  • 项目类别:
    Grant-in-Aid for Early-Career Scientists
Strategy Logics for the Verification of Security Protocols
安全协议验证的策略逻辑
  • 批准号:
    EP/V009214/1
  • 财政年份:
    2021
  • 资助金额:
    --
  • 项目类别:
    Research Grant
SaTC: CORE: Small: Formal Verification Techniques For Microprocessor Security Vulnerabilities and Trojans
SaTC:核心:小型:微处理器安全漏洞和特洛伊木马的形式验证技术
  • 批准号:
    2117190
  • 财政年份:
    2021
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
geneXwell: Multidimensional Omic Risk Models and Dynamic Visualizations to Drive Positive Change in Employee Behavioral Economics
geneXwell:多维组学风险模型和动态可视化推动员工行为经济学的积极变化
  • 批准号:
    10325942
  • 财政年份:
    2021
  • 资助金额:
    --
  • 项目类别:
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了