首页> 外文会议>2013 3rd International Workshop on Model-Driven Requirements Engineering >Security requirements formalized with OCL in a model-driven approach
【24h】

Security requirements formalized with OCL in a model-driven approach

机译:通过模型驱动方法与OCL一起制定安全要求

获取原文
获取原文并翻译 | 示例

摘要

Security requirements are properties that have to be guaranteed for an application. Such guarantees can be given using verification. But there is a huge gap between security requirements expressed with human language and formal security properties that can be verified. This paper presents the use of OCL to formalize security requirements in a model-driven approach for security-critical applications. SecureMDD is such a model-driven approach. It uses UML to model the application and OCL to specify the security requirements. From the application model and the contained OCL constraints, a formal specification of the application including the security properties is generated automatically. This specification is used to verify application-specific security properties that matches a lot of security requirements much better than application-independent security properties like secrecy, integrity and confidentiality. We demonstrate how to concretize security requirements as well as the use of OCL constraints to specify security requirements, the transformation from OCL constraints into algebraic specifications and the use of those specifications to verify the security requirements using an electronic ticketing system as a case study.
机译:安全要求是应用程序必须保证的属性。可以使用验证方式提供此类保证。但是,用人类语言表达的安全要求与可以验证的正式安全属性之间存在巨大差距。本文介绍了使用OCL在安全性关键应用程序的模型驱动方法中形式化安全要求。 SecureMDD是这种模型驱动的方法。它使用UML对应用程序进行建模,并使用OCL来指定安全要求。根据应用程序模型和所包含的OCL约束,会自动生成包含安全属性的应用程序正式规范。该规范用于验证与许多安全要求相匹配的特定于应用程序的安全性,其性能远胜于与应用程序无关的安全性,例如保密性,完整性和机密性。我们将演示如何具体化安全要求,以及如何使用OCL约束条件来指定安全要求,如何将OCL约束条件转换为代数规范以及如何使用这些规范来通过电子售票系统验证安全要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号