FP6Individual fellowship2007–2008

RSMC · Implementing access control mechanisms using rewriting techniques

FP6 — Marie Curie Actions (Human Resources and Mobility)

Duration
2007-05-01 → 2008-04-30
EU contribution
€47,274
Participants
1
Scheme
EIF

Lines connect the coordinator with its partners.

Results in brief

Final Activity Report Summary - RSMC (Implementing access control mechanisms using rewriting techniques)

Term rewriting systems are usually defined through the specification of a set of terms and a set of rewrite rules that are used to ‘reduce’ terms. This simple idea is very powerful, and term rewriting techniques have had deep influence in the development of computational models, specification languages, theorem provers and proof assistants. More recently, rewriting systems have been used as a formal basis for the study of a broad range of security issues. In this project we focussed on the specification, implementation and validation of security policies. The project general goal was to provide a deep analysis of access control models and policies using rewriting. We developed access control policies for centralised or distributed systems using a term rewriting framework. In order to do this, we extended the usual notion of rewriting to accommodate distributed code and investigated a theory of access control described in terms of a set of rewrite rules and their reductions. We applied our framework to the problem of policy combinations via a set of algebraic operators and we showed how to build a global policy which was consistent with its local specifications. Moreover, we took advantage of the existing tools and rewrite techniques to study the properties of the rewrite system, such as termination and confluence which related directly to properties of the access control policy, such as consistency and totality. This was then used as a starting point for the design of a rewrite-based language with access control primitives.

Data: CORDIS, © European Union

Project objective

Static behavioural analysis of mobile computer programs is an active area of research, many fundamental behavioural properties and security issues for mobile computing have to be established. We believe that rewriting can provide a formal basis for the study of a broad range of security issues, ranging from the specification, implementation, and validation of security policies, to the analysis of logs and the development of tools for intrusion detection.In this project we will focus mainly on access control within distributed and mobile applications. Special language primitives and reasoning tools are needed to specify access control policies and to prove their properties. The purpose of this project is to tackle this problem by using a well-known tool: rewriting theory, possibly combined with type systems. We plan to develop an implementation of the existing access control mechanisms, supported by centralised or distributed systems, using a term rewriting framework.We will extend the usual notion of rewriting to accommodate distributed code and investigate a theory of access control described in terms of a set of rewrite rules and their reductions. The rewrite system thus obtained will be used as a basis for the design of a distributed, mobile language where programs are defined as collections of rewrite rules with built-in mobility and access control mechanisms. The obtained rewrite-based language will be applicable in mobile distributed environments, in particular the Semantic Web environment.An advantage of the rewriting framework over a more traditional logic-programming framework is its expressivity: rewriting encompasses several computation paradigms, including functional, logic, imperative and concurrent ones. Another advantage is that we can profit from the rapid prototyping tools available, and we can study the behavioural and security properties of the reduction relation by using type systems and standard rewriting techniques.

Original text from CORDIS.

Participants

Links

Data: CORDIS, © European Union