Proceedings of the Eleventh ACM Symposium on Access Control Models and Technologies - SACMAT '06 2006
DOI: 10.1145/1133058.1133080
|View full text |Cite
|
Sign up to set email alerts
|

Information flow property preserving transformation of UML interaction diagrams

Abstract: We present an approach for secure information flow property preserving refinement and transformation of UML inspired interaction diagrams. The approach is formally underpinned by trace-semantics. The semantics is sufficiently expressive to distinguish underspecification from explicit nondeterminism. A running example is used to introduce the approach and to demonstrate that it is of practical value.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
9
0

Year Published

2007
2007
2013
2013

Publication Types

Select...
4
2

Relationship

2
4

Authors

Journals

citations
Cited by 10 publications
(9 citation statements)
references
References 29 publications
(42 reference statements)
0
9
0
Order By: Relevance
“…Roscoe [Ros95] defines Low-determinism, a very strong notion of security, which is always preserved under refinement, but at the cost of a significantly restricted range of applicability. Some recent works have also sought to overcome the refinement paradox by drawing a distinction between specification-level non-determinism and non-determinism that is inherent in a system, with the latter preserved under refinement [SS06,Jür05,Bib06].…”
Section: Related Workmentioning
confidence: 99%
“…Roscoe [Ros95] defines Low-determinism, a very strong notion of security, which is always preserved under refinement, but at the cost of a significantly restricted range of applicability. Some recent works have also sought to overcome the refinement paradox by drawing a distinction between specification-level non-determinism and non-determinism that is inherent in a system, with the latter preserved under refinement [SS06,Jür05,Bib06].…”
Section: Related Workmentioning
confidence: 99%
“…Roscoe [Ros95] defines Lowdeterminism, a very strong notion of security, which is always preserved under refinement, but at the cost of a significantly restricted range of applicability. Some recent works have also sought to overcome the refinement paradox by drawing a distinction between specification-level non-determinism and non-determinism that is inherent in a system, with the latter preserved under refinement [SS06,Jür05,Bib06].…”
Section: Related Workmentioning
confidence: 99%
“…Others have identified sufficient conditions for behavioral refinement to preserve information flow properties [GCS91, O'H92, BFPR03,Ros95]. Some recent works have also sought to overcome the refinement paradox by drawing a distinction between specificationlevel non-determinism and non-determinism that is inherent in a system, with the latter preserved under refinement [SS06,Jür05,Bib06].…”
Section: Related Workmentioning
confidence: 99%
“…Unpredictability in the form of non-determinism is known to be problematic in relation to specifications because non-determinism is also often used to represent underspecification and when underspecification is refined away during system development we may easily also reduce the required unpredictability and thereby reduce security. For this reason, STAIRS (as explained carefully by Seehusen and Stølen [21]) distinguishes between mandatory and potential choice. Mandatory choice is used to capture unpredictability while potential choice captures underspecification.…”
Section: Generalising the Semantics To Support Unpredictabilitymentioning
confidence: 99%