Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/2422498.2422508acmconferencesArticle/Chapter ViewAbstractPublication PagesmodelsConference Proceedingsconference-collections
research-article

A tool for the synthesis of cryptographic orchestrators

Published: 01 October 2012 Publication History
  • Get Citation Alerts
  • Abstract

    Security is one of the main challenges of service oriented computing. Services need to be loosely coupled, easily accessible and yet provide tight security guarantees enforced by cryptographic protocols. In this paper, we address how to automatically synthesize an orchestrator process able to guarantee the secure composition of electronic services, supporting different communication and cryptographic protocols. We present a theoretical model based on process algebra, partial model checking and logical satisfiability, plus an automated tool implementing the proposed theory.

    References

    [1]
    PaMoChSA 2012. http://www.iit.cnr.it/staff/vincenzo.ciancia/tools.html.
    [2]
    H. R. Andersen. Partial model checking. In LICS, page 398. IEEE, 1995.
    [3]
    Y. Chevalier, M. A. Mekki, and M. Rusinowitch. Automatic composition of services with security policies. In SERVICES'08 - Part I, pages 529--537. IEEE, 2008.
    [4]
    J. Li, M. Yarvis, and P. Reiher. Securing distributed adaptation. Computer Networks, 38(3), 2002.
    [5]
    O. Maler, A. Pnueli, and J. Sifakis. On the synthesis of discrete controllers for timed systems. In STACS, volume 900 of LNCS, pages 229--242. Springer, 2005.
    [6]
    J. A. Martín, F. Martinelli, and E. Pimentel. Synthesis of secure adaptors. J. Log. Algebr. Program., 81(2):99--126, 2012.
    [7]
    J. A. Martín and E. Pimentel. Contracts for security adaptation. J. Log. Algebr. Program., 80(3--5):154--179, 2011.
    [8]
    F. Martinelli. Analysis of security protocols as open systems. TCS, 290(1):1057--1106, 2003.
    [9]
    F. Martinelli and I. Matteucci. A framework for automatic generation of security controller. STVR, 2010.
    [10]
    F. Martinelli, M. Petrocchi, and A. Vaccarelli. Automated analysis of some security mechanisms of SCEP. In ISC, pages 414--427. Springer, 2002.
    [11]
    R. Milner. Communication and concurrency. Prentice-Hall, 1989.
    [12]
    C. Stirling. Modal and temporal logics for processes. In Logics for Concurrency: Structures versus Automata, pages 149--237, 1996.
    [13]
    R. S. Streett and E. A. Emerson. An automata theoretic decision procedure for the propositional mu-calculus. Information and Computation, 81(3):249--264, June 1989.
    [14]
    L. Viganò. Automated security protocol analysis with the AVISPA tool. ENTCS, 155:69--86, 2006.

    Cited By

    View all
    • (2014)Partial Model Checking for the Verification and Synthesis of Secure Service CompositionsPublic Key Infrastructures, Services and Applications10.1007/978-3-642-53997-8_1(1-11)Online publication date: 2014
    • (2014)On the Synthesis of Secure Services CompositionEngineering Secure Future Internet Services and Systems10.1007/978-3-319-07452-8_6(140-159)Online publication date: 2014
    • (2013)Automated Synthesis and Ranking of Secure BPMN OrchestratorsProceedings of the 2013 International Conference on Availability, Reliability and Security10.1109/ARES.2013.60(455-464)Online publication date: 2-Sep-2013

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Conferences
    MDsec '12: Proceedings of the Workshop on Model-Driven Security
    October 2012
    57 pages
    ISBN:9781450318068
    DOI:10.1145/2422498
    Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

    Sponsors

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 01 October 2012

    Permissions

    Request permissions for this article.

    Check for updates

    Author Tags

    1. partial model checking
    2. process algebras
    3. secure service composition
    4. synthesis of functional and secure processes
    5. temporal logic

    Qualifiers

    • Research-article

    Conference

    MODELS '12
    Sponsor:

    Upcoming Conference

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)1
    • Downloads (Last 6 weeks)0

    Other Metrics

    Citations

    Cited By

    View all
    • (2014)Partial Model Checking for the Verification and Synthesis of Secure Service CompositionsPublic Key Infrastructures, Services and Applications10.1007/978-3-642-53997-8_1(1-11)Online publication date: 2014
    • (2014)On the Synthesis of Secure Services CompositionEngineering Secure Future Internet Services and Systems10.1007/978-3-319-07452-8_6(140-159)Online publication date: 2014
    • (2013)Automated Synthesis and Ranking of Secure BPMN OrchestratorsProceedings of the 2013 International Conference on Availability, Reliability and Security10.1109/ARES.2013.60(455-464)Online publication date: 2-Sep-2013

    View Options

    Get Access

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media