Specification and Implementation of secure web systems
Specification and Implementation of secure web systems
批准号:
356630-2007
负责人:
Frappier, Marc
金额:
$7.23万
依托单位:
依托单位国家:
加拿大
项目类别:
Strategic Projects Supplemental Competition
财政年份:
2007
资助国家:
加拿大
项目状态:
已结题
起止时间:
2007-01-01 至 2008-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Information systems are prevalent in today's economy. Nowadays, they are intensively distributed andaccessible over the Internet. To facilitate their construction, deployment, maintenance and improve theiraccessibility, they are now constructed as web services which may be invoked over the Internet from arbitrarylocations. These information systems convey private, valuable information which must be only accessed byauthorized personnel. Several domains like financial systems and patient records are subject to strictregulations like Sarbane-Oxley, HIPAAA, and PIPEDA. Security and privacy are addressed using severaltechnology like authentication, encryption and secure communication protocols. We are targeting anotheraspect of security, which we call functional security. It describes the security rules that are at the businessrequirements level. For instance, the investment account of a customer should only be accessible to its brokerand his manager; the health record of a patient should only be available to its treating doctor or limitedinformation could be made available for a limited time period to consulting specialists. There are variouslevels at which functional security can be specified : data attributes, atomic services (actions) and businessprocess (a complex ordering of atomic services). This project will: i) propose a specification method forfunctional security policies for web systems at these three levels; ii) define synthesis algorithms toautomatically implement functional security policies into a security kernel, within the context of aservice-oriented architecture. Functional security policies will be specified separately from functionalrequirements, in order to facilitate their maintenance and implementation. The security kernel implementingthese policies will be separated from the implementation of the functional requirements, enabling onlinemodification of security rules without having to modify the implementation of the services. Our approach isbased on formal methods, enabling the use of formal verification techniques to ensure the consistency andadequacy of security policies.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A formal approach to intrusion detection
-
批准号:RGPIN-2019-05327
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to intrusion detection
-
批准号:RGPIN-2019-05327
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2021
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to intrusion detection
-
批准号:RGPIN-2019-05327
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2020
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to intrusion detection
-
批准号:RGPIN-2019-05327
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to access control and consent management
-
批准号:RGPIN-2014-04162
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2018
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to access control and consent management
-
批准号:RGPIN-2014-04162
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2017
-
负责人:Frappier, Marc
-
依托单位:
Methods and techniques for the automation and simplification of ICS honey pots deployments and monitoring
-
批准号:508278-2017
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2017
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to access control and consent management
-
批准号:RGPIN-2014-04162
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2016
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to access control and consent management
-
批准号:RGPIN-2014-04162
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2015
-
负责人:Frappier, Marc
-
依托单位:
A formal approach to access control and consent management
-
批准号:RGPIN-2014-04162
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2014
-
负责人:Frappier, Marc
-
依托单位:
Formal reuse and validation of information system specifications/Réutilisation et validation formelle des spécifications de systèmes d'information
-
批准号:185805-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.8万
-
财政年份:2013
-
负责人:Frappier, Marc
-
依托单位:
Formal reuse and validation of information system specifications/Réutilisation et validation formelle des spécifications de systèmes d'information
-
批准号:185805-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.8万
-
财政年份:2012
-
负责人:Frappier, Marc
-
依托单位:
Formal reuse and validation of information system specifications/Réutilisation et validation formelle des spécifications de systèmes d'information
-
批准号:185805-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.8万
-
财政年份:2011
-
负责人:Frappier, Marc
-
依托单位:
Formal reuse and validation of information system specifications/Réutilisation et validation formelle des spécifications de systèmes d'information
-
批准号:185805-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.8万
-
财政年份:2010
-
负责人:Frappier, Marc
-
依托单位:
Formal reuse and validation of information system specifications/Réutilisation et validation formelle des spécifications de systèmes d'information
-
批准号:185805-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.8万
-
财政年份:2009
-
负责人:Frappier, Marc
-
依托单位:
Specification and Implementation of secure web systems
-
批准号:356630-2007
-
项目类别:Strategic Projects Supplemental Competition
-
资助金额:$7.23万
-
财政年份:2008
-
负责人:Frappier, Marc
-
依托单位:
Synthèse automatique de systèmes d'information
-
批准号:185805-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.8万
-
财政年份:2008
-
负责人:Frappier, Marc
-
依托单位:
Synthèse automatique de systèmes d'information
-
批准号:185805-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.8万
-
财政年份:2007
-
负责人:Frappier, Marc
-
依托单位:
Synthèse automatique de systèmes d'information
-
批准号:185805-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.8万
-
财政年份:2006
-
负责人:Frappier, Marc
-
依托单位:
Synthèse automatique de systèmes d'information
-
批准号:185805-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.8万
-
财政年份:2005
-
负责人:Frappier, Marc
-
依托单位:
海外基金