Formal Modelling and Implementation of Clark-Wilson Security Policy with FoCaLiZe
 No Thumbnail Available 
Date
2024
Journal Title
Journal ISSN
Volume Title
Publisher
Institute of Electrical and Electronics Engineers
Abstract
The security of every system hinges on a robust policy that orchestrates controls to safeguard the confidentiality, integrity, and accessibility of information. Implementing such a policy requires meticulous formulation grounded in mathematical and logical precision. In this context, we present a formal modeling and implementation of the Clark-Wilson security method using the FoCaLiZe environment, a workshop equipped with certification capabilities, where programming is intertwined with formal proof. The proposed approach enables the specification of the Clark-Wilson policy constraints and security principles as properties and theorems within FoCaLiZe. Thanks to Zenon, the automatic theorem prover of FoCaLiZe, derived properties and theorems that ensure system safety can be checked and proven.
Description
Keywords
Security policy, Clark-Wilson policy, Formal Methods, Zenon, FoCaLiZe, Modelling
