Security Verification of Software with Dynamic Access Control
Security Verification of Software with Dynamic Access Control
批准号:
14580376
负责人:
SEKI Hiroyuki
金额:
$2.05万
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research (C)
财政年份:
2002
资助国家:
日本
项目状态:
已结题
起止时间:
2002 至 2003
中文摘要
访问控制策略是一种规则,描述了指定主体何时以及在何种条件下可以(或不能或必须)对指定目标执行指定操作。其行为由策略控制的程序被称为策略控制系统(PCS)。在这项研究中,我们首先定义了一个简单的策略规范语言。该语言具有足够的结构来描述积极/消极的授权和义务。基于该语言形式化地定义了PCS的操作语义,并将PCS的安全性验证问题定义为对给定的PCS S和目标(称为安全性)φ,判定P的每个可达状态是否满足φ的问题。我们已经实现了一个验证工具的PCS,其工作原理如下。首先,下推系统(PDS)是从PCS抽象和非确定有限自动机(NFA),它接受的PDS的所有可达状态的集合被构造。对一个1.7K行的复杂责任策略的PCS进行验证的计算时间约为几分钟,这表明所提出的验证方法对真实的世界程序是可行的。通过将PDS扩展到树结构,定义了广义生长TRS(GG-TRS)子类。我们表明,对于一个任意的GG-TRS,保持可识别性,LTL(线性时序逻辑)模型检查是可判定的。此外,作为验证方法的应用,我们已经实现了一个工具,它验证是否一个给定的XML文档满足给定的可访问性准则。我们已经使用该工具验证了美国和日本40个主要组织的约3,000个网页。
英文摘要
A policy for access control is a rule describing when and on which condition a specified subject can (or cannot or must) perform a specified action on a specified target. A program of which behavior is controlled by a policy is called a policy controlled system (PCS). In this research, we first define a simple policy specification language. The language has a structure sufficient for describing positive/negative authorization and obligation. We formally define the operational semantics of PCS based on the language.Next, we define the (safety) verification problem for PCS as the problem to decide for a given PCS S and a goal (called safety property) φ, whether every reachable state of P satisfies φ. We have implemented a verification tool for PCS, which works as follows. First, a pushdown system (PDS) is abstracted from a PCS and a nondeterministic finite automaton (NFA) which accepts the set of all reachable states of the PDS is constructed. The computation time is about a few minutes for verifying a PCS of 1.7K lines with complex obligation policy, which shows that the proposed verification method is feasible for real world programs.We extend the proposed method for verifying the property of term rewrite system (TRS). A subclass of TRS called generalized growing TRS (GG-TRS) is defined by extending PDS to tree structure. We show that for an arbitrary GG-TRS which preserves recognizability, an LTL (linear temporal logic) model checking is decidable. Also, as an application of the verification method, we have implemented a tool which verifies whether a given XML document satisfies a given accessibility guideline. We have verified about 3,000 web pages of forty major organizations in the U.S.A.and Japan using the tool.
期刊论文(46)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Hiroyuki Seki, Naoya Nitta, Yoshiaki Takata, Shigeta Kuninobu: "Infinite State Model Checking and Its Application to Software Verification"第2回クリティカルソフトウェアワークショップ予稿集. 20-22 (2003)
Hiroyuki Seki、Naoya Nitta、Yoshiaki Takata、Shigeta Kuninobu:“无限状态模型检查及其在软件验证中的应用”第二届关键软件研讨会论文集 20-22 (2003)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
八木勲, 高田喜朗, 関浩之: "ラベル付き遷移システムに基づくアスペクト指向プログラムのモデル化"電子情報通信学会技術研究報告. SS2003-46. 1-6 (2004)
Isao Yagi、Yoshiro Takada、Hiroyuki Seki:“基于标记转换系统的面向方面的程序建模” IEICE 技术报告 SS2003-46 (2004)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Y.Takata, T.Nakamura, H.Seki: "Accessibility Verification of WWW Documents by an Automatic Guideline Verification Tool"37^<th> Annual Hawaii Int'l Conference on System Sciences, the Digital Documents and Media Track. (Full Paper : CD-ROM). Abstract:98 (20
Y.Takata、T.Nakamura、H.Seki:“通过自动指南验证工具对 WWW 文档进行可访问性验证”第 37 届夏威夷系统科学、数字文档和媒体领域国际会议。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
毛利寿志, 高田喜朗, 関浩之: "システムの内部状態を導入した信用管理モデル"電子情報通信学会2004年総合大会講演論文集. A-7-2 (2004)
Hisashi Mori、Yoshiro Takada、Hiroyuki Seki:“结合系统内部状态的信任管理模型”2004 年电子、信息和通信工程师协会大会记录 A-7-2 (2004)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Kuninobu, Takata, Taguchi, Nakae, Seki: "A Specification Languge for Distributed Policy Control"4th Int'l. Conf. on Information and Communications Security. LNCS2513. 386-398 (2002)
Kuninobu、Takata、Taguchi、Nakae、Seki:“分布式策略控制的规范语言”第四届国际会议。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
共 20 条
RNA-protein interaction prediction based on machine learning and optimization
-
批准号:23650153
-
项目类别:Grant-in-Aid for Challenging Exploratory Research
-
资助金额:$2.33万
-
财政年份:2011
-
负责人:SEKI Hiroyuki
-
依托单位:
Automatic Analys is and Generation Methods for Language-based Access Control
-
批准号:20500034
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.83万
-
财政年份:2008
-
负责人:SEKI Hiroyuki
-
依托单位:
STUDY ONAUTOMATIC VERIFICATION OF HIGHLY RELIABLE SOFTWARE BYINFINITE STATE MODEL CHECKING
-
批准号:18500023
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.48万
-
财政年份:2006
-
负责人:SEKI Hiroyuki
-
依托单位:
FORMAL VERIFICATION METHOD OF ACTIVE SOFTWARE
-
批准号:16500019
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.18万
-
财政年份:2004
-
负责人:SEKI Hiroyuki
-
依托单位:
The study of cytokines, as a regulator on the proliferation, invasion and differentiation of trophoblasts.
-
批准号:08671921
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$1.41万
-
财政年份:1996
-
负责人:SEKI Hiroyuki
-
依托单位:
海外基金