Authors:
Michel Embe Jiague
1
;
Marc Frappier
1
;
Frédéric Gervais
2
;
Pierre Konopacki
1
;
Régine Laleau
2
;
Jérémy Milhau
1
and
Richard St-Denis
1
Affiliations:
1
Université de Sherbrooke, Canada
;
2
Université Paris-Est, France
Keyword(s):
Security model, Security policy, Specification, Verification, Process algebra, Hierarchical state transition diagram, EB3SEC, EB3, MDA, SOA, BPEL.
Related
Ontology
Subjects/Areas/Topics:
Enterprise Information Systems
;
Formal Methods
;
Information Systems Analysis and Specification
;
Methodologies and Technologies
;
Modeling Formalisms, Languages and Notations
;
Operational Research
;
Security
;
Simulation and Modeling
Abstract:
This paper describes an ongoing project on the specification and automatic implementation of functional security policies. We advocate a clear separation between functional behavior and functional security requirements. We propose a formal language to specify functional security policies. We are developing techniques by which a formal functional security policy can be automatically implemented. Hence, our approach is highly inspired from model-driven engineering. Furthermore, our formal language will enabled us to use model checking techniques to verify that a security policy satisfies desired properties.