Early Validation and Verification of a Distributed Role-Based Access Control Model

File Size Format
58721_1.pdf 403Kb Adobe PDF View
Title Early Validation and Verification of a Distributed Role-Based Access Control Model
Author Zafar, Saad Naeem; Colvin, Robert; Winter, Kirsten; Yatapanage, Nisansala Prasanthi; Dromey, Geoff
Publication Title Proceedings 14th Asia-Pacific Software Engineering Conference, 2007. APSEC 2007
Year Published 2007
Publisher IEEE
Abstract To ensure correct implementation of complex access control requirements, it is important that the validated and verified requirements are effectively integrated with the rest of the system. It is also important that the system can be validated and verified early in the development process. In this paper we present an integrated, role-based access control model. The model is based on the graphical Behavior Tree notation, and can be validated by simulation, as well as verified using a model checker. Using this model, access control requirements can be integrated with the rest of the system from the outset, because: a single notation is used to express both access control and functional requirements; a systematic and incremental approach to constructing a formal Behavior Tree specification can be adopted; and the specification can be simulated and model checked. The effectiveness of the model is evaluated using a case study with distributed access control requirements.
Peer Reviewed Yes
Published Yes
Publisher URI http://ieeexplore.ieee.org/servlet/opac?punumber=4425817
Alternative URI http://dx.doi.org/10.1109/ASPEC.2007.20
Copyright Statement Copyright 2007 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
Conference name 14th Asia-Pacific Software Engineering Conference, 2007. APSEC 2007
Location Nagoya, Aichi, Japan
Date From 2007-12-04
Date To 2007-12-07
Date Accessioned 2009-12-04
Date Available 2009-12-04T05:23:22Z
Language en_AU
Faculty Faculty of Science, Environment, Engineering and Technology
Subject PRE2009-Cross discipline
Publication Type Conference Publications (Full Written Paper - Refereed)
Publication Type Code e1a

Brief Record

Griffith University copyright notice