Brucker, A.D., Rittinger, F. and Wolff, B. (2002) A CVS-Server Security Architecture — Concepts and Formal Analysis. Technical Report. Technical Report (182). Albert-Ludwigs-Universität Freiburg , Freiburg.
Abstract
We present a secure architecture of a CVS-server, its implementation (i.e. mainly its configuration) and its formal analysis. Our CVS-server is uses cvsauth, that provides protection of passwords and protection of some internal data of the CVS repository. In contrast to other (security oriented) CVS-architectures, our approach allows the CVS-server run on an open filesystem, i.e. a filesystem where users can have direct access both by CVS-commands and by standard UNIX/POSIX commands such as mv. For our secure architecture of the CVS-server, we provide a formal specification and security analysys. The latter is based on a refinement mapping high-level security requirements on the architecture on low-level security mechanisms on the UNIX/POSIX filesystem level. The purpose of the formal analysis of the secure CVS-server architecture is twofold: First, it is the bases for the specification of mutual security properties such as non-repudiation, authentication and access control for this architecture. Second, the mapping of the architecture on standard security implementation technology is described. Thus, our approach can be seen as a method to give a formal underpinning for the usually tricky business of system administrators.
Metadata
Item Type: | Monograph |
---|---|
Authors/Creators: |
|
Dates: |
|
Institution: | The University of Sheffield |
Academic Units: | The University of Sheffield > Faculty of Engineering (Sheffield) > Department of Computer Science (Sheffield) |
Depositing User: | Symplectic Sheffield |
Date Deposited: | 24 Feb 2016 12:51 |
Last Modified: | 27 Mar 2016 18:23 |
Published Version: | http://tr.informatik.uni-freiburg.de/2002/Report18... |
Status: | Published |
Publisher: | Albert-Ludwigs-Universität Freiburg |
Series Name: | Technical Report |
Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:95545 |