Securing Multi-party distributed systems is still a challenge. In such distributed systems with completely distributed interactions between parties with mutual distrust, it is hard to control private information illicit flowing to unintended parties. Unlike some existent solutions dealing with low-level cryptographic protocol verifications in multi-party interactions, we propose a novel approach based model transformations to build a secure-by-construction multi-party distributed system. The user has only to describe his system in a component-based model with multiparty interactions and annotate these components and interactions to define the system security policy. The system security is checked and when valid, the security code is automatically generated. To validate the approach, we present a framework that implements our method and use it to secure an existent online social network application.

Sylvan ClebschImperial College London, Sophia DrossopoulouImperial College London
Stefan MarrINRIA, France, Hanspeter MössenböckJohannes Kepler University Linz
Shohei YasutakeTokyo Institute of Technology, Takuo WatanabeTokyo Institute of Technology
Najah Ben SaidVerimag, Takoua AbdellatifUniversity of Sousse, Saddek BensalemVerimag, Marius BozgaVerimag/CNRS