Formal specification and management of security policies with collective group obligations

被引:0
|
作者
Cuppens, Frederic [1 ]
Cuppens-Boulahia, Nora [1 ]
Elrakaiby, Yehia [2 ]
机构
[1] Telecom Bretagne, 2 Rue Chataigneriae, F-35512 Cesson Sevigne, France
[2] Univ Luxembourg, Luxembourg, Luxembourg
关键词
Obligations; group obligations; collective obligations; policy management; sanctions;
D O I
10.3233/JCS-2012-0459
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Obligations are an essential element of security policies since they enable the specification of many security requirements such as availability, privacy, usage control and data protection. In everyday life, the fulfillment of obligations is often the responsibility of more than one subject, e.g., "All patients must be checked by one of the doctors". Obligations may also be fulfilled in different ways, e.g., "Every customer should pay either in cash or by check". Current security policy languages do not enable the specification of these intuitive and much needed requirements. In this paper, we show how policy languages can be extended to support the specification of these requirements which we call group obligations. To clarify the semantics of group obligations, we introduce state-based models for both group and individual obligations and show how group obligations can be managed according to change in the state of individual obligations. We formalize the semantics of the model and interactions between individual and group obligations by introducing a policy-enforcement language LE. LE enables the formal description of the application domain and the policy and provides operational semantics for policy management. Moreover, we discuss termination and determinism of policy enforcement in the proposed framework and show how different sanction/reaction policies may be activated when group obligations are violated.
引用
收藏
页码:149 / 190
页数:42
相关论文
共 50 条
  • [1] Formal Specification and Validation of Security Policies
    Bourdier, Tony
    Cirstea, Horatiu
    Jaume, Mathieu
    Kirchner, Helene
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, 2011, 6888 : 148 - +
  • [2] Formal specification and integration of distributed security policies
    Mejri, Mohamed
    Yahyaoui, Hamdi
    [J]. COMPUTER LANGUAGES SYSTEMS & STRUCTURES, 2017, 49 : 1 - 35
  • [3] Agent Coordination Contexts for the formal specification and enactment of coordination and security policies
    Omicini, Andrea
    Ricci, Alessandro
    Viroli, Mirko
    [J]. SCIENCE OF COMPUTER PROGRAMMING, 2006, 63 (01) : 88 - 107
  • [4] Specification of contractual obligations in formal business communication
    Ryu, YU
    [J]. DATA & KNOWLEDGE ENGINEERING, 1998, 26 (03) : 309 - 326
  • [5] Formal Specification and Verification of Security Guidelines
    Zhioua, Zeineb
    Roudier, Yves
    Ameur, Rabea Boulifa
    [J]. 2017 IEEE 22ND PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC 2017), 2017, : 267 - 273
  • [6] Towards formal specification and generation of autonomic policies
    Sterritt, R
    Hinchey, MG
    Rash, JL
    Truszkowski, W
    Rouff, CA
    Gracanin, D
    [J]. EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005 WORKSHOPS, PROCEEDINGS, 2005, 3823 : 1245 - 1254
  • [7] The specification and enforcement of advanced security policies
    Ryutov, T
    Neuman, C
    [J]. THIRD INTERNATION WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2002, : 128 - 138
  • [8] Specification and runtime enforcement of security policies
    Jin, Ying
    Zhang, Jing
    Zheng, Xiaojuan
    [J]. 2007 IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING WORKSHOPS, PROCEEDINGS, 2007, : 244 - +
  • [9] XML scheme for specification of security policies
    Monteiro, Pedro
    Verde, Joao Vila
    Souto, Pedro
    [J]. ACTAS DA 1A CONFERENCIA IBERICA DE SISTEMAS E TECNOLOGIAS DE INFORMACAO, VOL II, 2006, : 391 - 404
  • [10] Specification and verification of security policies in firewalls
    Jalili, R
    Rezvani, M
    [J]. EURASIA-ICT 2002: INFORMATION AND COMMUNICATION TECHNOLOGY, PROCEEDINGS, 2002, 2510 : 154 - 163