Erzhuo Chen

dblp:296/3541 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0001-0215-4893ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Detecting Errors in NGAC Policies via Fault-Based Testing
abstract
Next Generation Access Control (NGAC) is a standard for implementing dynamic attribute-based access control. It allows access events to trigger programmed administrative obligations and change access privileges during policy execution. However, complex obligations in an NGAC application have the potential of “grave harm to the authorization state through error or intent.” The existing work on NGAC policy testing and verification has limited effectiveness in detecting obligation errors. To address this limitation, we present a novel fault-based testing approach to determining the presence or absence of errors in NGAC policies. It hypothesizes potential errors (faults) in the given policy according to a comprehensive fault model, represents the corrected versions by policy mutants, and validates the hypotheses by generating and executing distinguishing tests. The distinguishing test of a mutant ensures that the mutant and the policy yield distinct execution results – the hypothetical error is present in the policy if the policy's execution result is wrong. We have implemented the approach based on the NGAC reference implementation and applied it to two case studies, including the first fully-fledged NGAC application with sophisticated obligations. The experiment results demonstrate that (a) the subject policies are absent from all hypothetical faults, and (b) all faulty policies represented by the mutants are revealed by fault-based tests. The results also show that the obligation tests targeting individual faults have effectively revealed multi-fault errors. Thus, the proposed approach can help detect potential errors in the development process of NGAC applications.
Erzhuo Chen, Vladislav Dubrovenski, Dianxiang Xu
IEEE Trans. Dependable Secur. Comput.1
2023 SMT-Based Verification of NGAC Policies
abstract
Next Generation Access Control (NGAC) is a standard for implementing attribute-based access control in computer software. It allows for run-time privilege changes through administrative obligations triggered by access events. However, incorrect privilege changes due to error or intent can cause grave harm to the authorization state. It is important to ensure that the run-time privilege changes meet the access control requirements. To address this issue, we present an efficient approach to verifying NGAC policies by leveraging SMT to deal with complex policy structures and semantics. We have implemented our approach based on the NGAC reference implementation and applied it to two case studies, including the first and only fully-fledged NGAC application. We have formalized 259 access control requirements and successfully verified them against the subject policies. To further evaluate the error detection capability of our approach, we have verified 205 policy versions with a single-seeded obligation error and 154 versions with multiple-seeded obligation errors. The verification results show that all faulty policies failed to satisfy the requirements, and thus the errors were revealed.
Vladislav Dubrovenski, Erzhuo Chen, Dianxiang Xu
COMPSAC2
2023 Coverage-Based Testing of Obligations in NGAC Systems
abstract
The administrative obligation is a unique feature of Next Generation Access Control (NGAC), a standard for implementing fine-grained attribute-based access control. It provides a programming mechanism for run-time privilege changes by attaching administrative operations to authorized access events. However, dynamic privilege change raises a major concern because the application of NGAC has the potential of "grave harm to the authorization state through error or intent." It is important to reveal potential obligation errors that lead to incorrect privileges and privilege changes. To address this issue, this paper presents a family of coverage-based test generation methods for the obligations in NGAC applications. These methods can generate obligation tests to achieve the corresponding coverage criterion (obligation coverage, action coverage, decision coverage, or factor decision coverage). Each test consists of a sequence of obligation-triggering access events. We have applied the proposed methods to three NGAC applications. The experiment results demonstrate that they have different levels of fault-detection capability and cost-effectiveness.
Erzhuo Chen, Vladislav Dubrovenski, Dianxiang Xu
SACMAT1
2021 Mutation Analysis of NGAC Policies
abstract
The NGAC (Next Generation Access Control) standard for attribute-based access control (ABAC) allows for run-time changes of the permission and prohibition configurations through administrative obligations triggered by access events. It makes access control more fine-grained and dynamic. However, it raises challenges for assuring the correctness of NGAC policies. As policy testing is an important technique for quality assurance, this paper presents an approach to mutation analysis of NGAC policies. It can evaluate the effectiveness of a testing method and reveal potential faults in an inadequately tested policy. The mutation analysis covers various types of potential faults in the assignments, associations, prohibitions, and obligations of NGAC policies. This paper also proposes an incremental testing approach that first validates the initial configuration of a policy and then the policy as a whole. It helps determine whether faults appear in the configuration or the obligations. To evaluate the work, we have developed four working policies and their test suites based on the current NGAC reference implementation. The empirical studies show that the mutation analysis can shed light on the strengths and weaknesses of the test suites. They also demonstrate the need for developing more cost-effective testing methods.
Erzhuo Chen, Vladislav Dubrovenski, Dianxiang Xu
SACMAT1