Specification and Implementation of secure web systems
安全网络系统的规范和实施
基本信息
- 批准号:356630-2007
- 负责人:
- 金额:$ 7.23万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Strategic Projects Supplemental Competition
- 财政年份:2007
- 资助国家:加拿大
- 起止时间:2007-01-01 至 2008-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Information systems are prevalent in today's economy. Nowadays, they are intensively distributed andaccessible over the Internet. To facilitate their construction, deployment, maintenance and improve theiraccessibility, they are now constructed as web services which may be invoked over the Internet from arbitrarylocations. These information systems convey private, valuable information which must be only accessed byauthorized personnel. Several domains like financial systems and patient records are subject to strictregulations like Sarbane-Oxley, HIPAAA, and PIPEDA. Security and privacy are addressed using severaltechnology like authentication, encryption and secure communication protocols. We are targeting anotheraspect of security, which we call functional security. It describes the security rules that are at the businessrequirements level. For instance, the investment account of a customer should only be accessible to its brokerand his manager; the health record of a patient should only be available to its treating doctor or limitedinformation could be made available for a limited time period to consulting specialists. There are variouslevels at which functional security can be specified : data attributes, atomic services (actions) and businessprocess (a complex ordering of atomic services). This project will: i) propose a specification method forfunctional security policies for web systems at these three levels; ii) define synthesis algorithms toautomatically implement functional security policies into a security kernel, within the context of aservice-oriented architecture. Functional security policies will be specified separately from functionalrequirements, in order to facilitate their maintenance and implementation. The security kernel implementingthese policies will be separated from the implementation of the functional requirements, enabling onlinemodification of security rules without having to modify the implementation of the services. Our approach isbased on formal methods, enabling the use of formal verification techniques to ensure the consistency andadequacy of security policies.
信息系统在当今经济中很普遍。如今,它们广泛分布在互联网上。为了方便它们的构建、部署、维护和提高它们的可访问性,它们现在被构建为可以在互联网上从任意位置调用的Web服务。这些信息系统传递的是私人的、有价值的信息,只有经过授权的人员才能访问。金融系统和病历等多个领域都受到严格的监管,如Sarbane-Oxley,HIPAAA和PIPEDA。安全性和隐私性是使用几种技术来解决的,如身份验证、加密和安全通信协议。我们的目标是安全的另一个方面,我们称之为功能安全。它描述了业务需求级别的安全规则。例如,客户的投资账户应该只允许其经纪人及其经理人访问;病人的健康记录应该只提供给其治疗医生,或者有限的信息可以在有限的时间内提供给咨询专家。功能安全可以在不同的级别上指定:数据属性、原子服务(操作)和业务流程(原子服务的复杂排序)。该项目将:i)在这三个层次上提出了Web系统功能安全策略的规范方法; ii)定义了在面向服务的体系结构中自动实现功能安全策略的合成算法。功能安全政策将与功能要求分开规定,以便于其维护和实施。实现这些策略的安全内核将与功能需求的实现分离,从而实现在线修改安全规则,而无需修改服务的实现。我们的方法是基于形式化的方法,使使用形式化的验证技术,以确保安全策略的一致性和充分性。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Frappier, Marc其他文献
Proof-based verification approaches for dynamic properties: application to the information system domain
- DOI:
10.1007/s00165-014-0323-x - 发表时间:
2015-03-01 - 期刊:
- 影响因子:1
- 作者:
Mammar, Amel;Frappier, Marc - 通讯作者:
Frappier, Marc
SGAC: A Multi-Layered Access Control Model with Conflict Resolution Strategy
- DOI:
10.1093/comjnl/bxz039 - 发表时间:
2019-12-01 - 期刊:
- 影响因子:1.4
- 作者:
Nghi Huynh;Frappier, Marc;Laleau, Regine - 通讯作者:
Laleau, Regine
Frappier, Marc的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Frappier, Marc', 18)}}的其他基金
A formal approach to intrusion detection
入侵检测的正式方法
- 批准号:
RGPIN-2019-05327 - 财政年份:2022
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to intrusion detection
入侵检测的正式方法
- 批准号:
RGPIN-2019-05327 - 财政年份:2021
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to intrusion detection
入侵检测的正式方法
- 批准号:
RGPIN-2019-05327 - 财政年份:2020
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to intrusion detection
入侵检测的正式方法
- 批准号:
RGPIN-2019-05327 - 财政年份:2019
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to access control and consent management
访问控制和同意管理的正式方法
- 批准号:
RGPIN-2014-04162 - 财政年份:2018
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to access control and consent management
访问控制和同意管理的正式方法
- 批准号:
RGPIN-2014-04162 - 财政年份:2017
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
Methods and techniques for the automation and simplification of ICS honey pots deployments and monitoring
用于自动化和简化 ICS 蜜罐部署和监控的方法和技术
- 批准号:
508278-2017 - 财政年份:2017
- 资助金额:
$ 7.23万 - 项目类别:
Engage Grants Program
A formal approach to access control and consent management
访问控制和同意管理的正式方法
- 批准号:
RGPIN-2014-04162 - 财政年份:2016
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to access control and consent management
访问控制和同意管理的正式方法
- 批准号:
RGPIN-2014-04162 - 财政年份:2015
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
A formal approach to access control and consent management
访问控制和同意管理的正式方法
- 批准号:
RGPIN-2014-04162 - 财政年份:2014
- 资助金额:
$ 7.23万 - 项目类别:
Discovery Grants Program - Individual
相似海外基金
Collaborative Research: Implementation: Medium: Secure, Resilient Cyber-Physical Energy System Workforce Pathways via Data-Centric, Hardware-in-the-Loop Training
协作研究:实施:中:通过以数据为中心的硬件在环培训实现安全、有弹性的网络物理能源系统劳动力路径
- 批准号:
2320972 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Standard Grant
Collaborative Research: Implementation: Medium: Secure, Resilient Cyber-Physical Energy System Workforce Pathways via Data-Centric, Hardware-in-the-Loop Training
协作研究:实施:中:通过以数据为中心的硬件在环培训实现安全、有弹性的网络物理能源系统劳动力路径
- 批准号:
2320975 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Standard Grant
Implementation of an impact assessment tool to optimize responsible stewardship of genomic data in the cloud
实施影响评估工具以优化云中基因组数据的负责任管理
- 批准号:
10721762 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Collaborative Research: Implementation: Medium: Secure, Resilient Cyber-Physical Energy System Workforce Pathways via Data-Centric, Hardware-in-the-Loop Training
协作研究:实施:中:通过以数据为中心的硬件在环培训实现安全、有弹性的网络物理能源系统劳动力路径
- 批准号:
2320973 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Standard Grant
Collaborative Research: Implementation: Medium: Secure, Resilient Cyber-Physical Energy System Workforce Pathways via Data-Centric, Hardware-in-the-Loop Training
协作研究:实施:中:通过以数据为中心的硬件在环培训实现安全、有弹性的网络物理能源系统劳动力路径
- 批准号:
2320974 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Standard Grant
Assessing risk for firearm injury and attitudes about new gun violence prevention laws in Michigan to enhance policy implementation
评估密歇根州枪伤风险和对新枪支暴力预防法的态度,以加强政策实施
- 批准号:
10811214 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Implementation of Mobile Medication Units for Patients with Opioid Use Disorder in New York.
在纽约为阿片类药物使用障碍患者建立移动医疗单位。
- 批准号:
10809880 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
ImpleMEntation of a Digital-first care deLiverY model for heart failure in Uganda (MEDLY Uganda)
在乌干达实施数字优先的心力衰竭护理服务模式 (MEDLY Uganda)
- 批准号:
10568129 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
CyberTraining: Implementation: Small: Promoting AI Readiness for Machine-Assisted Secure Data Analysis (PAIR4MASDA)
网络培训:实施:小型:促进人工智能为机器辅助安全数据分析做好准备 (PAIR4MASDA)
- 批准号:
2320951 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别:
Standard Grant
Assessing Implementation of Pharmacy-Based Medication Disposal Programs: National Estimates, Neighborhood Inequities, and Determinants of Implementation
评估基于药房的药物处置计划的实施情况:国家估计、社区不平等和实施的决定因素
- 批准号:
10590006 - 财政年份:2023
- 资助金额:
$ 7.23万 - 项目类别: