Slim Kallel

dblp:96/2929 · DBLP profile ↗
← Back
43ranked-venue papers
10as first author
13since 2021 · last 2025
0000-0002-2824-167XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 7 · 2 first-authorSystems, architecture and hardware · 6 · 1 first-author · 3 since 2021Security and privacy · 4 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Computer networks · 2Databases, data management, data science and information retrieval · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Blockchain-Powered Certificate Verification Enhanced by Self-Sovereign Identity and Off-Chain Caching
abstract
The proliferation of fraudulent certificates not only erodes trust but also deceives employers and academic organizations, making it harder to verify the qualifications of applicants and employees. Our blockchain-based web application, enhanced with self-sovereign identity (SSI), addresses these challenges by ensuring the authenticity and integrity of academic credentials. Graduates gain full control over their credentials through SSI, allowing them to securely manage, share, and verify their qualifications independently. Educational institutions, in turn, benefit from streamlined processes such as bulk certificate generation and QR code-enabled verification, all within a decentralized and tamper-proof framework enabled by SSI. Additionally, we provide an off-chain cache to further enhance system efficiency by alleviating the blockchain’s load and achieving optimal response times for frequently accessed credentials.
Saoussen Cheikhrouhou, Mariem Turki, Slim Kallel, Amal Abid 0002, Mohamed Jmaiel
IWCMC3
2025 Managing Model Evolution from NoSQL Data Lakes to Decision Support Systems
Said Taktak, Zoubair Mabrouk, Slim Kallel, Ahmed Hadj Kacem
MEDI3
2024 A Smart Contract-Based Access Control Framework For Smart Healthcare Systems
abstract
Abstract Security faces huge challenges in Internet of Things (IoT) environments. In particular, conventional access control standards and models tend to be less tailored for IoT due to the constrained nature of smart objects. Usually, a powerful third party is used to handle the access control logic. However, this third party is lacking in transparency and could harm user privacy. Therefore, providing a distributed access control solution, while considering transparency and privacy-preserving awareness in IoT smart systems, is of paramount importance. The described issue can be addressed using the emergent Blockchain technology that provides a promising choice to build a new generation of decentralized and transparent access control solutions. This paper proposes a smart contract-based access control framework for IoT smart healthcare systems, which is based on smart contracts to provide a distributed and trustworthy access control, combined with the GTRBAC model to express fine-grained access control policies while considering temporal authorization constraints. To prove the feasibility and validity of the proposed framework, this paper also provides a detailed technical description and an initial implementation and execution. An experimental evaluation shows that security properties’ analyses on smart contracts achieved the best possible evaluation with no vulnerabilities found, and the cost of access control operations increases linearly as the number of policy constraints increases. Besides, a comparative analysis reveals that the proposed approach can achieve good results with low gas costs and latency.
Amal Abid 0002, Saoussen Cheikhrouhou, Slim Kallel, Zahir Tari, Mohamed Jmaiel
Comput. J.3
2023 A survey on automation approaches of smart contract generation
Rawya Mars, Saoussen Cheikhrouhou, Slim Kallel, Ahmed Hadj Kacem
J. Supercomput.3
2022 Towards a Secure Cross-Blockchain Smart Contract Architecture
Rawya Mars, Saoussen Cheikhrouhou, Slim Kallel, Mohamed Sellami, Ahmed Hadj Kacem
CRiSIS3
2022 A Blockchain-Based Self-Sovereign Identity Approach for Inter-Organizational Business Processes
abstract
Blockchain presents a promising and revolutionary technology for organizations' collaboration, particularly for Inter-Organizational Business Processes (IOBP).It addresses the lack-of-trust problem thanks to its transparency and decentralized features.However, while the adoption of Blockchain technology can alleviate some of IOBP's challenges, it does so at the expense of significant privacy issues.In fact, some process execution data, such as customers' data or business secrets, cannot be shared across the collaborating organizations owing to regulatory restrictions such as the General Data Protection Regulation (GDPR).To address trust and privacy issues in IOBP, this paper presents a Blockchain-based Self-Sovereign Identity (SSI) approach.The SSI concept is combined with a registry proof smart contract to provide an efficient privacy-preserving solution.The proposed approach is applied to the pharmaceutical supply chain case study and implemented on the Ethereum Blockchain.
Amal Abid 0002, Saoussen Cheikhrouhou, Slim Kallel, Mohamed Jmaiel
FedCSIS3
2022 Model-Driven Simulation of Elastic OCCI Cloud Resources
abstract
Abstract Deploying a cloud configuration in a real cloud platform is mostly cost- and time- consuming, as large number of cloud resources have to be rented for the time needed to run the configuration. Thereafter, cloud simulation tools are used as a cheap alternative to test cloud configuration. However, most of the existing cloud simulation tools require extensive technical skills and do not support simulation of any kind of cloud resources. In this context, using a model-driven approach can be helpful as it allows developers to efficiently describe their needs at a high level of abstraction. To do, we propose, in this article, a model-driven engineering approach based on the Open Cloud Computing Interface(OCCI) standard metamodel and CloudSim toolkit. We firstly extend OCCI metamodel for the supporting simulation of any kind of cloud resources. Afterward, to illustrate the extensibility of our approach, we enrich the proposed metamodel by new simulation capabilities. As proof of concept, we study the elasticity and pricing strategies of Amazon Web Services (AWS). This article benefits from OCCIware Studio to design an OCCI simulation extension and to provide a simulation designer for designing cloud configurations to be simulated. We detail the approach process from defining an OCCI simulation extension until the generation and the simulation of the OCCI cloud configurations. Finally, we validate the proposed approach by providing a realistic experimentation to study its usability, the resources coverage rate and the cost. The results are compared with the ones computed from AWS.
Mehdi Ahmed-Nacer, Slim Kallel, Faiez Zalila, Philippe Merle, Walid Gaaloul
Comput. J.2
2022 A time interval-based approach for business process fragmentation over cloud and edge resources
Saoussen Cheikhrouhou, Zakaria Maamar, Rawya Mars, Slim Kallel
Serv. Oriented Comput. Appl.4
2022 NovidChain: Blockchain-based privacy-preserving platform for COVID-19 test/vaccine certificates
abstract
The COVID-19 pandemic has emerged as a highly transmissible disease which has caused a disastrous impact worldwide by adversely affecting the global economy, health, and human lives. This sudden explosion and uncontrolled worldwide spread of COVID-19 has revealed the limitations of existing healthcare systems regarding handling public health emergencies. As governments seek to effectively re-establish their economies, open workplaces, ensure safe travels and progressively return to normal life, there is an urgent need for technologies that may alleviate the severity of the losses. This article explores a promising solution for secure Digital Health Certificate, called NovidChain, a Blockchain-based privacy-preserving platform for COVID-19 test/vaccine certificates issuing and verifying. More precisely, NovidChain incorporates several emergent concepts: (i) Blockchain technology to ensure data integrity and immutability, (ii) self-sovereign identity to allow users to have complete control over their data, (iii) encryption of Personally Identifiable Information to enhance privacy, (iv) W3C verifiable credentials standard to facilitate instant verification of COVID-19 proof, and (v) selective disclosure concept to permit user to share selected pieces of information with trusted parties. Therefore, NovidChain is designed to meet a high level of protection of personal data, in compliant with the GDPR and KYC requirements, and guarantees the user's self-sovereignty, while ensuring both the safety of populations and the user's right to privacy. To prove the security and efficiency of the proposed NovidChain platform, this article also provides a detailed technical description, a proof-of-concept implementation, different experiments, and a comparative evaluation. The evaluation shows that NovidChain provides better financial cost and scalability results compared to other solutions. More precisely, we note a high difference in time between operations (i.e., between 46% and 56%). Furthermore, the evaluation confirms that NovidChain ensures security properties, particularly data integrity, forge, binding, uniqueness, peer-indistinguishability, and revocation.
Amal Abid 0002, Saoussen Cheikhrouhou, Slim Kallel, Mohamed Jmaiel
Softw. Pract. Exp.3
2021 A Machine Learning Approach for Gas Price Prediction in Ethereum Blockchain
abstract
Ethereum is a blockchain-based platform that pro-vides a global computational infrastructure to run smart contracts. In order to assign a cost to smart contract and transaction execution, the Ethereum Blockchain adopts a gas-based metering approach which is designed to motivate miners to operate the network and protect it against attacks. More precisely, miners receive fees from all transactions included in the mined block in addition to the mining reward. Hence, the higher the gas price in the transactions, the higher the fee paid to the miner will be, resulting in faster selection and execution of higher priced gas transactions. Therefore, an Ethereum transaction sender is exposed to the non-trivial task of having to choose an optimal gas price, as underpaying likely results in a transaction not being picked by miners, whereas overpaying leads to superfluous costs. This paper provides recommendation approach that proposes an appropriate gas price to users. More precisely, it investigates different approaches of forecasting algorithms applied for gas price predictions for the next block in Ethereum Blockchain. The gas price is predicted using the Prophet model and the deep learning models, Long-Short Term Memory (LSTM) and Gated Recurrent Unit (GRU). It also aims to compare these approaches with the most used gas price oracles. An evaluation of the obtained results show that the LSTM and GRU proposed models outperform Prophet model as well as the gas price oracle Geth. In this case, LSTM and GRU provide a low mean squared error (MSE) of 0,008 whereas Geth gives an MSE of 0.016 and Prophet gives an MSE of 0.014.
Rawya Mars, Amal Abid 0002, Saoussen Cheikhrouhou, Slim Kallel
COMPSAC4
2021 Restriction-based fragmentation of business processes over the cloud
abstract
Summary Despite the elasticity and pay‐per‐use benefits of cloud computing (aka fifth utility computing), organizations adopting clouds could be locked into single cloud providers, which is not always a “pleasant” experience when these providers stop operations. This is a serious concern for those organizations that who would like to deploy (core) business processes on the cloud along with tapping into these two benefits. To address the lock‐into concern, this paper proposes an approach for decomposing business processes into fragments that would run over multiple clouds and hence multiple providers. To develop fragments, the approach considers both restrictions over owners of business processes and potential competition among cloud providers. On the one hand, restrictions apply to each task in a business process and are specialized into budget to allocate, deadline to meet, and exclusivity to request. On the other hand, competition leads cloud providers to offer flexible pricing policies that would cater to the needs and requirements of each process owner. A policy handles certain clouds' properties referred to as limitedness, non‐renewability, and non‐shareability that impact the availability of cloud resources and hence the whole fragmentation. For instance, a non‐shareable resource could delay other processes should the current process do not release this resource on time. During fragmentation, interactions between owners of processes and providers of clouds happen according to two strategies referred to as global and partial. The former collects offers about cloud resources from all providers, while the latter collects such details from particular providers. To evaluate these strategies' pros and cons, a system implementing them, as well as demonstrating the technical feasibility of the fragmentation approach using credit‐application case study, is also presented in the paper. The system extends BPMN2‐modeler Eclipse plugin and supports interactions of processes' owners with clouds' providers that result to identifying the necessary fragments with focus on cost optimization.
Slim Kallel, Zakaria Maamar, Mohamed Sellami, Noura Faci, Ahmed Ben Arab, Walid Gaaloul, Thar Baker
Concurr. Comput. Pract. Exp.1
2021 Special issue on risk and security of smart systems
Slim Kallel, Frédéric Cuppens, Nora Cuppens, Ahmed Hadj Kacem, Lotfi Ben Othmane
J. Inf. Secur. Appl.1
2021 Optimal business process deployment cost in cloud resources
Rania Ben Halima, Slim Kallel, Mehdi Ahmed-Nacer, Walid Gaaloul
J. Supercomput.2
2020 How blockchain helps to combat trust crisis in COVID-19 pandemic?: poster abstract
abstract
The COVID-19 pandemic is sweeping across the world and causing widespread death and disruption. To this effect, nations have struggled to use technologies to detect and to monitor COVID-19 cases and related information. Unfortunately, both inconsistent and inaccurate information from "trustless" sources, and "mistrust" in effectively monitoring and reporting patients symptoms and condition have highlighted the failure of existing infrastructures to preserve human healthcare while maintaining patient's privacy and to slow down the widespread of the pandemic. This paper provides an insight of the perceived benefits of Blockchain to expectations of the COVID-19 pandemic in terms of providing "trust" in addressing information sharing in health systems while maintaining privacy. This paper exhibits a Blockchain-based COVID-19 Smart Healthcare approach that embraces Blockchain's benefits in healthcare systems.
Amal Abid 0002, Saoussen Cheikhrouhou, Slim Kallel, Mohamed Jmaiel
SenSys3
2020 A comprehensive survey on modeling of cyber-physical systems
abstract
Summary Modeling Cyber‐physical systems (CPS) is a challenging step that requires a lot of background from both the cyber and physical fields. However, there is a lack of studies in the existing literature that discuss the state of the art in modeling CPS or explore the research gaps in this area. In this paper, we survey existing approaches to modeling CPS. We focus on studying the considered CPS properties. Based on this study, we classify these properties and discuss their importance in different application domains. Moreover, research directions are presented to address key challenges in the specification of CPS models.
Imen Graja, Slim Kallel, Nawal Guermouche, Saoussen Cheikhrouhou, Ahmed Hadj Kacem
Concurr. Comput. Pract. Exp.2
2020 Toward a correct and optimal time-aware cloud resource allocation to business processes
Rania Ben Halima, Slim Kallel, Walid Gaaloul, Zakaria Maamar, Mohamed Jmaiel
Future Gener. Comput. Syst.2
2019 A Model-based Approach for the Modeling and the Verification of Railway Signaling System
abstract
International audience
Racem Bougacha, Abderrahim Ait Wakrime, Slim Kallel, Rahma Ben Ayed, Simon Collart Dutilleul
ENASE3
2019 Modelling and verifying time-aware processes for cyber-physical environments
abstract
Cyber‐physical systems (CPSs) are characterized by a multitude of physical and software. Particularly time‐related properties are of paramount importance and they can impact the behaviour of these systems. Designing and verifying CPS while tackling time‐related and physical properties are very important steps in the CPS life cycle development. Indeed, it is necessary to capture and characterize the different features and their dependencies with time through expressive models. Then, these models must be verified to prove their correctness. Existing process modelling languages such as business process modelling notation (BPMN) has been widely used to model business processes. However, BPMN lacks several features for modelling rich CPS processes such as those related to time and physical properties. In this study, the authors propose a verification framework for collaborative time‐aware CPS processes. In this context, they propose to extend BPMN to support the various CPS concepts and properties. Based on this extension, they propose a consistency verification approach, which aims to verify that the time‐related and physical properties associated with each process do not give rise to conflicts. Finally, they propose a compatibility verification approach, which aims to verify that the set of involved CPS processes form consistent inter‐CPS processes.
Imen Graja, Slim Kallel, Nawal Guermouche, Saoussen Cheikhrouhou, Ahmed Hadj Kacem
IET Softw.2
2018 Formal Verification of Temporal Constraints and Allocated Cloud Resources in Business Processes
abstract
Cloud environments offer an interesting infrastructure for any modern enterprise information systems due to their high performance and low operating cost. Cloud resources are offered in various pricing strategies based on temporal properties. In general, enterprises looking towards minimizing their spending on IT infrastructure find such pricing strategies very attractive to deploy and run their business processes. Nevertheless, due to the lack of explicit and formal description of (Cloud) resources in existing business processes modeling languages, such as BPMN, Cloud resources can not be correctly allocated. Therefore, we elaborate an extension to BPMN 2.0 to fully integrate (Cloud) resource perspective, especially the temporal properties of Cloud pricing strategies in business process model. In order to help the designer to allocate correctly the required Cloud resources, we propose an automatic generation of timed automata from this BPMN extensions to check the matching between both temporal constraints: activities and Cloud resources. To show its feasibility, our approach has been implemented and tested using a real use case from an industrial partner.
Rania Ben Halima, Imen Zouaghi, Slim Kallel, Walid Gaaloul, Mohamed Jmaiel
AINA3
2018 Specification and automatic checking of architecture constraints on object oriented programs
Sahar Kallel, Chouki Tibermacine, Slim Kallel, Ahmed Hadj Kacem, Christophe Dony
Inf. Softw. Technol.3
2017 Modeling and verification of temporal properties in cyber-physical systems
abstract
Cyber-physical systems (CPS) enable the development of complex real-world applications through the integration of computational and physical processes. The resulting processes are usually constrained by hard timing and physical requirements. These requirements are of paramount importance and must be handled at the different steps of the CPS process life cycle: from modeling until execution. Business Process Modeling Notation (BPMN) enables us to model processes in general. Even if BPMN provides a rich notation to cater for relevant features of process modeling, its capabilities are limited to capturing specific CPS processes properties, particularly physical and temporal properties. On the other hand, it is necessary to verify these properties to ensure that CPS can operate in a provably correct manner. In this paper, we focus on the problem of modeling and verifying CPS processes according to physical and temporal properties. To do so, we first propose to extend BPMN to handle specific CPS processes. Based on this extension, we propose a verification approach which relies on a constraint satisfaction model to check the consistency of the considered properties.
Imen Graja, Slim Kallel, Nawal Guermouche, Ahmed Hadj Kacem
CCNC2
2017 Demonstrating BPMN4CPS: Modeling anc verification of cyber-physical systems
abstract
Modeling is one of the most important topics in the area of Cyber-Physical Systems (CPS). By using BPMN4CPS [1], a designer can model CPS and their temporal properties as a set of collaborative and communicating processes organized in three parts: a cyber part, a controller part, and a physical part. However, the designer might specify a faulty combination of properties that can cause temporal violations. To address this problem and to check the consistency of the given properties, our tool automatically translates a CPS process model to a constraint satisfaction model. In this paper, we illustrate how to implement the BPMN4CPS approach and we demonstrate the capabilities of our tool.
Imen Graja, Aicha Mechim, Slim Kallel, Nawal Guermouche, Ahmed Hadj Kacem
CCNC3
2017 AROSA 2017: Summary Report
abstract
Presents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record.
Ismael Bouassida Rodriguez, Slim Kallel, Mohamed Jmaiel, Khalil Drira
WETICE2
2017 An approach based on runtime models for developing dynamically adaptive systems
Sihem Loukil, Slim Kallel, Mohamed Jmaiel
Future Gener. Comput. Syst.2
2016 Time patterns for cyber-physical systems
abstract
Cyber-physical systems (CPS) are a set of physical entities controlled by software systems to reach a specific goal under temporal and physical resource constraints. Existing research pays little attention to the modeling of CPS at the business process layer, and is lacking in considering the temporal dimension. In this paper, we present a set of time patterns applied to the cyber and physical elements of CPS processes. We model this process using a directed graph with associated time and time-dependent constraints.
Imen Graja, Slim Kallel, Nawal Guermouche, Ahmed Hadj Kacem
ISCC2
2016 BPMN4CPS: A BPMN Extension for Modeling Cyber-Physical Systems
abstract
Modeling is one of the most important topics in the domain of Cyber-Physical Systems (CPS). In the field of process modelling, Business Process Modeling and Notation (BPMN) is the most used standard. However, BPMN remains limited to cater for the specific characteristics and properties of CPS such as real world properties. In this paper, we propose BPMN4CPS, which provides a set of extensions for BPMN to properly and accurately model CPS processes. In order to illustrate the applicability of BPMN4CPS, we present a case study of an ambulance drone system.
Imen Graja, Slim Kallel, Nawal Guermouche, Ahmed Hadj Kacem
WETICE2
2016 Arosa Track Report
abstract
AROSA Track Report
Slim Kallel, Khalil Drira, Mohamed Jmaiel
WETICE1
2016 Adaptive and reconfigurable software systems and architectures
Slim Kallel, Ismael Bouassida Rodriguez, Khalil Drira
J. Syst. Softw.1
2015 AROSA 2015 Track Report: Adaptive and Reconfigurable Service-Oriented and Component-Based Applications and Architectures
abstract
The focal concerns are Service-oriented software systems, applications and architectures addressing adaptation and reconfiguration issues. Different investigation topics are involved, such as: SOA, requirements (QoS, performance), monitoring, diagnosis, decision and execution of adaptation and reconfiguration. Different research axes are covered: concepts, methods, techniques, and tools to design, develop, deploy and manage adaptive and reconfigurable software systems.
Slim Kallel, Ismael Bouassida Rodriguez, Mohamed Jmaiel
WETICE1
2015 Enabling Technologies: Infrastructure for Collaborative Enterprises
abstract
Slim Kallel, Mohamed Jmaiel, Sumitra Reddy; Enabling Technologies: Infrastructure for Collaborative Enterprises, The Computer Journal, Volume 58, Issue 3, 1 Mar
Slim Kallel, Mohamed Jmaiel, Sumitra Reddy
Comput. J.1
2015 The temporal perspective in business process modeling: a survey and research challenges
Saoussen Cheikhrouhou, Slim Kallel, Nawal Guermouche, Mohamed Jmaiel
Serv. Oriented Comput. Appl.2
2014 An Approach for Security Patterns Application in Component Based Models
Rahma Bouaziz Kammoun, Slim Kallel, Bernard Coulette
ICCSA (5)2
2014 On Enabling Time-Aware Consistency of Collaborative Cross-Organisational Business Processes
Saoussen Cheikhrouhou, Slim Kallel, Nawal Guermouche, Mohamed Jmaiel
ICSOC2
2014 A Collaborative Process for Developing Secure Component Based Applications
abstract
Security patterns describe security solutions that can be used in a particular context for recurring problems in order to solve a security problem in a more structured and reusable way. Patterns in general and Security patterns in particular, have become important concepts in software engineering, and their integration is a widely accepted practice. In this paper, we propose a model-driven methodology for security pattern integration. This methodology consists of a collaborative engineering process, called collaborative security pattern Integration process (C-SCRIP), and a tool that supports the full life-cycle of the development of a secure system from modeling to code.
Rahma Bouaziz Kammoun, Slim Kallel, Bernard Coulette
WETICE2
2014 Toward a Verification of Time-Centric Business Process Models
abstract
Temporal constraints are one cornerstone of process specification and verification in the whole process lifecycle. Nevertheless, in the existing research approaches, little consideration has been given to the subject of verification of advanced temporal constraints such as absolute temporal constraints associated with relative temporal constraints. In this paper, we handle the problem of verification while considering advanced relative and absolute temporal constraints. Firstly, a set of rules are proposed to prevent the designer to specify some faulty temporal combinations of absolute temporal constraints, early on, before the execution step. Second, to capture relative temporal constraints, we propose a mapping step whose aim is to map timed business processes into timed automata. Using the defined formal model, we finally investigate a model checking based verification approach that aims at validating business processes against their temporal constraints.
Saoussen Cheikhrouhou, Slim Kallel, Mohamed Jmaiel
WETICE2
2014 Track Report of Adaptive and Reconfigurable Service-Oriented and Component-Based Applications and Architectures (AROSA 2014)
abstract
The goal of the AROSA track is to bring together researchers and practitioners both from the Academia and from the Industry working in the areas of Service-oriented and component-based software applications and architectures and addressing adaptation and reconfiguration issues.
Khalil Drira, Slim Kallel, Ismael Bouassida Rodriguez
WETICE2
2013 Toward a Time-centric modeling of Business Processes in BPMN 2.0
abstract
Business-to-business (B2B) e-commerce market is expected to expand rapidly in coming years. In this context, organizations tend to rely more on business process management (BPM) to streamline their operations. The business process field is influenced by a wide range of temporal constraints which rise from legal, regulatory, and managerial rules. One of the most promising standards for business process modeling, namely the Business process Model and notation BPMN poorly addresses the time dimension so far. In this paper, we elaborate an extension to BPMN 2.0 to handle the time dimension. The aim of this BPMN extensions is to support business analysts and modellers in easily including the needed temporal constraints in their processes. We motivate and justify our proposed extensions by means of illustrative case studies. Furthermore, based on the proposed extensions, a verification approach based on the model checking technique is used to diagnose potential temporal violations of the process model. The work presented in this paper sets foundation for later automation of these constraints through process execution engines.
Saoussen Cheikhrouhou, Slim Kallel, Nawal Guermouche, Mohamed Jmaiel
iiWAS2
2012 Modeling Secure Mobile Agent Systems
Molka Rekik, Slim Kallel, Monia Loulou, Ahmed Hadj Kacem
KES-AMSTA2
2012 Modeling and enforcing invariants of dynamic software architectures
Slim Kallel, Mohamed Hadj Kacem, Mohamed Jmaiel
Softw. Syst. Model.1
2010 Toward an Aspect Oriented ADL for Embedded Systems
Sihem Loukil, Slim Kallel, Bechir Zalila, Mohamed Jmaiel
ECSA2
2009 A holistic approach for access control policies: from formal specification to aspect-based enforcement
abstract
We present in this paper a novel approach to non-functional safety properties, combining formal methods and Aspect-Oriented Programming (AOP). The approach supports both the formal specification and the enforcement of such properties through runtime monitoring. We apply our approach for security policies and especially Role-Based Access Control (RBAC) policies including application-specific constraints such as separation of duties and delegation. For formal specification, we introduce TemporalZ, a formal language based on Z and temporal logic, which provides domain specific predicates for expressing RBAC policies. For the enforcement, we generate automatically modular enforcement code out of the formal specification using the aspect-oriented language ALPHA.
Slim Kallel, Anis Charfi, Mira Mezini, Mohamed Jmaiel, Andreas Sewe
Int. J. Inf. Comput. Secur.1
2008 Aspect-based enforcement of formal delegation policies
abstract
Delegation is a powerful concept in access control systems, which allows users to assign all or part of their permissions to other users. Several types of delegation models for role-based access control have been proposed so far. However, most existing works focus on the specification of delegation policies and there is very little work on the monitoring and enforcement of such policies at runtime. In this paper, we use a security approach combining formal methods and aspect-oriented programming for specifying and enforcing delegation policies. In our approach, delegation models and their characteristics are specified formally using TemporalZ, which is a combination of Z notation and temporal logic. Then, we verify the formal specification to ensure consistency using theorem proving. Finally, we generate automatically a set of aspects in the aspect-oriented language ALPHA from the TemporalZ specifications. These aspects enforce the specified delegation policies at runtime.
Slim Kallel, Anis Charfi, Mira Mezini, Mohamed Jmaiel
CRiSIS1
2007 Combining Formal Methods and Aspects for Specifying and Enforcing Architectural Invariants
Slim Kallel, Anis Charfi, Mira Mezini, Mohamed Jmaiel
COORDINATION1