• DocumentCode
    2445870
  • Title

    A formal security framework for mobile agent systems: Specification and verification

  • Author

    Loulou, Monia ; Kacem, Ahmed Hadj ; Jmaiel, Mohamed ; Mosbah, Mohamed

  • Author_Institution
    Lab. ReDCAD, Sfax
  • fYear
    2008
  • fDate
    28-30 Oct. 2008
  • Firstpage
    69
  • Lastpage
    76
  • Abstract
    Security in mobile agent systems is twofold: protection of mobile agents and protection of agent execution system. Indeed, the proposed solutions for the security of distributed systems arenpsilat sufficient. Moreover, therepsilas no solution which treats the different concerns of security in the mobile agent systems. To achieve this goal, we use formal foundations which provide a rigorous reasoning about security of mobile agent systems. We propose in this paper a formal framework for the security in mobile agent systems which consists of three basic frameworks. The specification framework proposes, explicitly, a generic definition of security policies that may be enhanced by several concepts related to one or more security models. For illustration, we present a security policy enhancement based on the concepts of the RBAC model. Inevitably, we associate to the specification framework a verification framework which checks the consistency of the proposed specifications as well as the consistency intra-policy. In response to the dynamic changes of security requirements in mobile agent systems, we propose a third framework for the reconfiguration of policies.
  • Keywords
    authorisation; distributed processing; formal specification; formal verification; mobile agents; RBAC model; agent execution system; distributed systems; formal security framework; mobile agent systems; role-based access control; specification framework; verification framework; Access control; Control systems; Internet; Laboratories; Mobile agents; Object oriented modeling; Protection; Resource management; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Risks and Security of Internet and Systems, 2008. CRiSIS '08. Third International Conference on
  • Conference_Location
    Tozeur
  • Print_ISBN
    978-1-4244-3309-4
  • Type

    conf

  • DOI
    10.1109/CRISIS.2008.4757465
  • Filename
    4757465