Article ID Journal Published Year Pages File Type
423550 Electronic Notes in Theoretical Computer Science 2009 18 Pages PDF
Abstract

Data protection within information systems is one of the main concerns in computer systems security and different access control policies can be used to specify the access requests that should be granted or denied. These access control mechanisms should guarantee that information can be accessed only by authorized users and thus prevent all information leakage. We propose a methodology for specifying and implementing access control policies using the rewrite based framework Tom. This approach allows us to check that any reachable state obtained following a granted access in the implementation satisfies the policy specification. We show that when security levels are not totally ordered some information leakage can be detected.

Related Topics
Physical Sciences and Engineering Computer Science Computational Theory and Mathematics