Skip to search boxSkip to navigationSkip to main content

In the Nick of Time: Proactive Prevention of Obligation Violations

Research Output:
Journal Article or Conference Article in Journal
Conference article
Peer-review

Open access

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Conference article
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 120-134 (15 pages)

Journal (Volume, Issue Number)

I E E E Computer Security Foundations Symposium. Proceedings

Publication milestones

  • Published - 11/08/2016

Publication status

Published - 11/08/2016

ISSN

1940-1434

Publication IDs

  • Scopus: 84985916954

Abstract

We present a system model, an enforcement mechanism, and a policy language for the proactive enforcement of timed provisions and obligations. Our approach improves upon existing formalisms in two ways: (1) we exploit the target system's existing functionality to avert policy violations proactively, rather than compensate for them reactively, and, (2) instead of requiring the manual specification of remedial actions in the policy, we automatically deduce required actions directly from the policy. As a policy language, we employ timed dynamic condition response (DCR) processes. DCR primitives declaratively express timed provisions and obligations as causal relationships between events, and DCR states explicitly represent pending obligations. As key technical results, we show that enforceability of DCR policies is decidable, we give a sufficient polynomial time verifiable condition for a policy to be enforceable, and we give an algorithm for determining from a DCR state a sequence of actions that discharge impending obligations.

Publication metrics

PlumX, opens in new tab

Citations
15
Captures
14

Related Event

Title

IEEE Computer Security Foundations Symposium

Event type

Conference

Degree of recognition

International event

Date

27/06/2016 - 01/07/2016

Location

LisbonPortugal