TY - GEN
T1 - Early validation and verification of a distributed role-based access control model
AU - Zafar, Saad
AU - Colvin, Robert
AU - Winter, Kirsten
AU - Yatapanage, Nisansala
AU - Dromey, R. G.
PY - 2007
Y1 - 2007
N2 - To ensure correct implementation of complex access control requirements, it is important that the validated and verified requirements are effectively integrated with the rest of the system. It is also important that the system can be validated and verified early in the development process. In this paper we present an integrated, role-based access control model. The model is based on the graphical Behavior Tree notation, and can be validated by simulation, as well as verified using a model checker. Using this model, access control requirements can be integrated with the rest of the system from the outset, because: a single notation is used to express both access control and functional requirements; a systematic and incremental approach to constructing a formal Behavior Tree specification can be adopted; and the specification can be simulated and model checked. The effectiveness of the model is evaluated using a case study with distributed access control requirements.
AB - To ensure correct implementation of complex access control requirements, it is important that the validated and verified requirements are effectively integrated with the rest of the system. It is also important that the system can be validated and verified early in the development process. In this paper we present an integrated, role-based access control model. The model is based on the graphical Behavior Tree notation, and can be validated by simulation, as well as verified using a model checker. Using this model, access control requirements can be integrated with the rest of the system from the outset, because: a single notation is used to express both access control and functional requirements; a systematic and incremental approach to constructing a formal Behavior Tree specification can be adopted; and the specification can be simulated and model checked. The effectiveness of the model is evaluated using a case study with distributed access control requirements.
UR - https://www.scopus.com/pages/publications/44949237938
U2 - 10.1109/APSEC.2007.46
DO - 10.1109/APSEC.2007.46
M3 - Conference Paper
AN - SCOPUS:44949237938
SN - 0769530575
SN - 9780769530574
T3 - Proceedings - Asia-Pacific Software Engineering Conference, APSEC
SP - 430
EP - 437
BT - Proceedings - 14th Asia-Pacific Software Engineering Conference, APSEC 2007
T2 - 14th Asia Pacific Software Engineering Conference, ASPCE 2007
Y2 - 4 December 2007 through 7 December 2007
ER -