kirancodes.me
To Proof Maintenance & Beyond!

ATLAS: From Access conTrol Language to ACSL Specifications

Julien Signoles, Khaoula Boukir, Amine Nasri

Abstract

Access control is a classical way to express which users are allowed to do which actions on which objects. Many formalisms study how to model access control policies. However, fewer works target formal verification of an actual implementation with respect to a given policy. This paper presents ATLAS, a new formal specification language for expressing access control policies. This language allows for modeling an access control policy, linking it to a source code, and generating automatically formal annotations in order to verify that a source code correctly implements the modeled policy. This workflow is implemented as a new Frama-C plugin that generates ACSL annotations, which can be proved by deductive verification or checked at runtime.

Related papers