TY - GEN
T1 - Policy composition based on Petri nets
AU - Huang, Hejiao
AU - Kirchner, Hélène
PY - 2009
Y1 - 2009
N2 - Security policies are one of the most fundamental elements of computer security. For secure interoperation and sharing resources among heterogeneous systems, local policies should correspondingly be integrated for designing a global policy. This paper addresses the problem in a formal way. It uses extended Petri net process to specify and verify security policies in a modular way. It defines four types of policy compositions such that the integrated policy is capable of handling resources sharing, simultaneously executing operations and embedding subpolicies into main policies in multiple heterogeneous systems. Furthermore, the global policy can preserve the fundamental policy properties, i.e., completeness, termination, consistency and confluence, and satisfy policy autonomy and security principles that are required for secure interoperation.
AB - Security policies are one of the most fundamental elements of computer security. For secure interoperation and sharing resources among heterogeneous systems, local policies should correspondingly be integrated for designing a global policy. This paper addresses the problem in a formal way. It uses extended Petri net process to specify and verify security policies in a modular way. It defines four types of policy compositions such that the integrated policy is capable of handling resources sharing, simultaneously executing operations and embedding subpolicies into main policies in multiple heterogeneous systems. Furthermore, the global policy can preserve the fundamental policy properties, i.e., completeness, termination, consistency and confluence, and satisfy policy autonomy and security principles that are required for secure interoperation.
UR - https://www.scopus.com/pages/publications/70449673607
U2 - 10.1109/COMPSAC.2009.169
DO - 10.1109/COMPSAC.2009.169
M3 - 会议稿件
AN - SCOPUS:70449673607
SN - 9780769537269
T3 - Proceedings - International Computer Software and Applications Conference
SP - 416
EP - 421
BT - Proceedings - 2009 33rd Annual IEEE International Computer Software and Applications Conference, COMPSAC 2009
PB - IEEE Computer Society
T2 - 33rd Annual IEEE International Computer Software and Applications Conference, COMPSAC 2009
Y2 - 20 July 2009 through 24 July 2009
ER -