Dynamic role authorization in multiparty conversations
From MaRDI portal
Abstract: Protocol specifications often identify the roles involved in communications. In multiparty protocols that involve task delegation it is often useful to consider settings in which different sites may act on behalf of a single role. It is then crucial to control the roles that the different parties are authorized to represent, including the case in which role authorizations are determined only at runtime. Building on previous work on conversation types with flexible role assignment, here we report initial results on a typed framework for the analysis of multiparty communications with dynamic role authorization and delegation. In the underlying process model, communication prefixes are annotated with role authorizations and authorizations can be passed around. We extend the conversation type system so as to statically distinguish processes that never incur in authorization errors. The proposed static discipline guarantees that processes are always authorized to communicate on behalf of an intended role, also covering the case in which authorizations are dynamically passed around in messages.
Recommendations
Cites work
- scientific article; zbMATH DE number 3464854 (Why is no real title available?)
- scientific article; zbMATH DE number 1304000 (Why is no real title available?)
- scientific article; zbMATH DE number 1890630 (Why is no real title available?)
- Combining behavioural types with security analysis
- Conversation types
- Correspondence assertions for process synchronization in concurrent communications
- Dynamic management of capabilities in a network aware coordination language
- Dynamic multirole session types
- Dynamic role authorization in multiparty conversations
- Hide and new in the \(\pi\)-calculus
- Information flow safety in multiparty sessions
- Programming Languages and Systems
- Protection in operating systems
- Regulating Data Exchange in Service Oriented Applications
- Session types for access and information flow control
- The \(\pi\)-calculus: A theory of mobile processes
- Types for role-based access control of dynamic web data
Cited in
(4)
This page was built for publication: Dynamic role authorization in multiparty conversations
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q315294)