Formal Verification of Authorization Policies for Enterprise Social Networks Using PlusCal-2
Author(s) -
Sabina Akhtar,
Ehtesham Zahoor,
Olivier Perrin
Publication year - 2018
Publication title -
lecture notes of the institute for computer sciences, social informatics and telecommunications engineering
Language(s) - English
Resource type - Book series
SCImago Journal Rank - 0.142
H-Index - 44
eISSN - 1867-822X
pISSN - 1867-8211
DOI - 10.1007/978-3-030-00916-8_49
Subject(s) - computer science , domain (mathematical analysis) , authorization , bridge (graph theory) , enterprise private network , access control , security domain , computer security , enterprise information security architecture , world wide web , medicine , mathematical analysis , mathematics
Information security research has been a highly active and widely studied research direction. In the domain of of Enterprise Social Networks (ESNs), the security challenges are amplified as they aim to incorporate the social technologies in an enterprise setup and thus asserting greater control on information security. Further, the security challenges may not be limited to the boundaries of a single enterprise and need to be catered for a federated environment where users from different ESNs can collaborate. In this paper, we address the problem of federated authorization for the ESNs and present an approach for combining user level policies with the enterprise policies. We present the formal verification technique for ESNs and how it can be used to identify the conflicts in the policies. It allows us to bridge the gap between user-centric or enterprise-centric approaches as required by the domain of ESN. We apply our specification of ESNs on a scenario and discuss the model checking results.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom