We consider the extension of fair event system specifications by
concepts of access control (prohibitions, user rights, and
obligations). We give proof rules for verifying that an access
control policy is correctly implemented in a system, and consider
preservation of access control by refinement of event systems.
Prohibitions and obligations are expressed as properties of traces
and are preserved by standard refinement notions of event
systems. Preservation of user rights is not guaranteed by
construction; we propose to combine implementation-level user rights
and obligations to implement high-level user rights.
@Article{mery:access,
author = {Dominique Méry and Stephan Merz},
title = {Specification and Refinement of Access Control},
journal = {Journal of Universal Computer Science},
year = 2007,
volume = 13,
number = 8,
pages = {1073--1093},
}
Stephan Merz
Last modified: Wed Jan 19 14:58:38 CET 2005