Operating System Access Control Vulnerability Detection via Model Checking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control mechanisms for operating systems face security vulnerabilities due to fragmentation issues and uncertainty in security strategies, with existing formal methods being too abstract and lacking practical applications in real systems.

Innovation Solution

A method based on model checking that analyzes security requirements, formalizes access control rules, abstracts the access control module, uses theorem proving for consistency, and performs state space exploration to detect potential security risks and vulnerabilities through incremental refinement and simulation of attack scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If formal methods are used to analyze system vulnerabilities, then security verification capability is improved, but the level of abstraction becomes too high and practical application in real systems deteriorates

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidpractical application capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the access control verification process into multiple formal models (ACL model, RBAC model, IBAC model) that can be independently analyzed and then integrated. Each model addresses specific aspects of access control, making the formal verification more manageable and applicable to real systems while maintaining high security verification capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between theoretical formal methods and practical systems by creating standardized formal models that serve as intermediaries. These models act as a bridge, translating real-world access control requirements into formal specifications that can be verified while maintaining connection to practical applications

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control rules are made more comprehensive to cover all security scenarios, then security coverage is improved, but system complexity and rule conflict probability increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidaccess control rule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides comprehensive access control rules into segmented formal models (ACL, RBAC, IBAC) that handle different security scenarios separately. This segmentation allows thorough security coverage while managing complexity by addressing specific access control aspects in dedicated models rather than one monolithic rule set

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial verification by focusing on specific critical access control scenarios in each formal model rather than attempting to verify all possible rules simultaneously. This approach achieves sufficient security coverage for critical functions while avoiding the overwhelming complexity of complete rule verification

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11868481B2Method for discovering vulnerabilities of operating system access control mechanism based on model checking
Publication Date: 2024.01.09 ZHEJIANG UNIV
  • US11868481B2 patent drawing
  • US11868481B2 patent drawing
  • US11868481B2 patent drawing

AI summary

This invention discloses a method for discovering vulnerabilities of operating system access control based on model checking. In this method, security attribute and security specifications of operating system access control module are analyzed to construct the access control model. To discover vulnerabilities in the model, security analysis is performed for access control functionality with theorem proving techniques, and consistency of abstract machine specification and correctness and completeness of the components are verified with model checking tools. This method provides theoretical and technical support for studies in the field of operating system security.