Skip to main content Skip to main navigation

Project

MORES2

Modelling and Refinement of Security Requirements on Data and Processes 2

  • Duration:
  • Research Topics
    Other
  • Application fields
    Other

MORES2 aims at the development of appropriate refinement techniques for workflow specifications. In particular, the notion of refinement to be developed has to support the refinement of the various aspects (e.g. activities, data, users) of workflows and also has to be able to translate the security properties to corresponding properties in other refinement levels. Translated security guarantees of higher abstraction levels will serve as initial building blocks for the verification of security properties on lower levels. However, we cannot expect that the notion of refinement will preserve the security guarantees in general because otherwise the arising restrictions would render such a refinement impracticable. Additionally, changing the abstraction level may also result in a refinement of the abilities of an attacker observing the workflow, which causes a change of how the required security guarantees are formulated. In MORES2 we will develop techniques to make use of security guarantees of higher abstraction levels in verifying the corresponding security properties on lower abstraction levels. We will provide a corresponding verification tool support based on existing interactive proof systems.

Sponsors

DFG - German Research Foundation

Hu737/5-2

DFG - German Research Foundation

Publications about the project

Thomas Bauereiß; Armando Pesenti Gritti; Andrei Popescu; Franco Raimondi

In: Journal of Automated Reasoning (JAR), Vol. 61, No. 1-4, Pages 113-139, Springer, Heidelberg, 12/2017.

To the publication

Victor Ferman; Dieter Hutter; Raul Monroy

In: Grigori Sidorov; Ulises Cortés (Hrsg.). Computación y Sistemas, Vol. 21, No. 1, Pages 101-114, Instituto Politécnico Nacional, Mexico, Mexico City, 4/2017.

To the publication

Thomas Bauereiß; Armando Pesenti Gritti; Andrei Popescu; Franco Raimondi

In: 2017 IEEE Symposium on Security and Privacy. IEEE Symposium on Security and Privacy (SP-17), May 22-24, San Jose, CA, USA, IEEE, 2017.

To the publication