Formal Modelling and Implementation of Clark-Wilson Security Policy with FoCaLiZe

No Thumbnail Available

Date

2024

Journal Title

Journal ISSN

Volume Title

Publisher

Institute of Electrical and Electronics Engineers

Abstract

The security of every system hinges on a robust policy that orchestrates controls to safeguard the confidentiality, integrity, and accessibility of information. Implementing such a policy requires meticulous formulation grounded in mathematical and logical precision. In this context, we present a formal modeling and implementation of the Clark-Wilson security method using the FoCaLiZe environment, a workshop equipped with certification capabilities, where programming is intertwined with formal proof. The proposed approach enables the specification of the Clark-Wilson policy constraints and security principles as properties and theorems within FoCaLiZe. Thanks to Zenon, the automatic theorem prover of FoCaLiZe, derived properties and theorems that ensure system safety can be checked and proven.

Description

Keywords

Security policy, Clark-Wilson policy, Formal Methods, Zenon, FoCaLiZe, Modelling

Citation

Endorsement

Review

Supplemented By

Referenced By