We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Possibilistic Information Flow Control for Workflow Management Systems

Abstract: In workflows and business processes, there are often security requirements on both the data, i.e. confidentiality and integrity, and the process, e.g. separation of duty. Graphical notations exist for specifying both workflows and associated security requirements. We present an approach for formally verifying that a workflow satisfies such security requirements. For this purpose, we define the semantics of a workflow as a state-event system and formalise security properties in a trace-based way, i.e. on an abstract level without depending on details of enforcement mechanisms such as Role-Based Access Control (RBAC). This formal model then allows us to build upon well-known verification techniques for information flow control. We describe how a compositional verification methodology for possibilistic information flow can be adapted to verify that a specification of a distributed workflow management system satisfies security requirements on both data and processes.
Comments: In Proceedings GraMSec 2014, arXiv:1404.1634
Subjects: Cryptography and Security (cs.CR)
Journal reference: EPTCS 148, 2014, pp. 47-62
DOI: 10.4204/EPTCS.148.4
Cite as: arXiv:1404.1987 [cs.CR]
  (or arXiv:1404.1987v1 [cs.CR] for this version)

Submission history

From: EPTCS [view email]
[v1] Tue, 8 Apr 2014 01:46:50 GMT (140kb,D)

Link back to: arXiv, form interface, contact.