Process algebra can save lives: static analysis of XACML access control policies using mCRL2

Hamed Arshad*, Ross Horne, Christian Johansen, Olaf Owe, Tim A.C. Willemse

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution book

1 Citation (Scopus)

Abstract

This paper proposes an approach to formally verify XACML policies using the process algebra mCRL2. XACML (eXtensible Access Control Markup Language) is an OASIS standard for access control systems that is much used in health care due to its fine-grained, attribute-based policy definitions, useful in dynamic environments such as emergency wards. A notorious problem in XACML is the detection of conflicts, which arise especially when combining policies, such as when health institutions merge. Our formal translation of XACML policies into mCRL2, using our automated tool XACML2mCRL2, enables us to verify the above property, called consistency, as well as other policy properties such as completeness and obligation enforcement. Verifying policy properties statically allows us to resolve inconsistencies in advance, thus avoiding situations where an access request is denied in a critical situation (e.g., in an ambulance, when lives may be put in danger) just because of incomplete or inconsistent policies. The mCRL2 toolset is especially useful for modeling behaviors of interactive systems, where XACML would be only one part. Therefore, we verify an access control system together with the intended health care system that it is supposed to protect. For this, we exemplify how to verify safety and liveness properties of an assisted living and community care system.

Original languageEnglish
Title of host publicationFormal Techniques for Distributed Objects, Components, and Systems - 42nd IFIP WG 6.1 International Conference, FORTE 2022, Held as Part of the 17th International Federated Conference on Distributed Computing Techniques, DisCoTec 2022, Proceedings
EditorsMohammad Reza Mousavi, Anna Philippou
PublisherSpringer Science and Business Media Deutschland GmbH
Pages11-30
Number of pages20
ISBN (Electronic)978-3-031-08679-3
ISBN (Print)978-3-031-08678-6
DOIs
Publication statusPublished - 12 Jun 2022
Event42nd IFIPWG6.1 International Conference on Formal Techniques for Distributed Objects, Components, and Systems, FORTE 2022 Held as Part of the 17th International Federated Conference on Distributed Computing Techniques, DisCoTec 2022 - Lucca, Italy
Duration: 13 Jun 202217 Jun 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13273 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference42nd IFIPWG6.1 International Conference on Formal Techniques for Distributed Objects, Components, and Systems, FORTE 2022 Held as Part of the 17th International Federated Conference on Distributed Computing Techniques, DisCoTec 2022
Country/TerritoryItaly
CityLucca
Period13/06/2217/06/22

Keywords

  • Access control
  • mCRL2
  • Process algebra
  • XACML

Fingerprint

Dive into the research topics of 'Process algebra can save lives: static analysis of XACML access control policies using mCRL2'. Together they form a unique fingerprint.

Cite this