首页> 外文会议>ICCSA 2011;International conference on computational science and its applications >Towards a Better Integration of Patterns in Secure Component-Based Systems Design
【24h】

Towards a Better Integration of Patterns in Secure Component-Based Systems Design

机译:在基于组件的安全系统设计中更好地集成模式

获取原文

摘要

Security has become an important challenge in current software and system development. Most of designers are experts in software development but not experts in security. It is important to guide them to decide how and where to apply security mechanisms in the early phases of software development to reduce time and cost of development. To reach this objective, we propose to apply security expertise as security patterns at software design phase. Our methodology is based on the use of a component metamodel to capture the domain concepts and security patterns to encode solutions to security problem. The expected result is a model as design solution for specific domain. Here, we promote a modeling technique based on UML profiles to facilitate the integration of patterns solutions into model driven engineering approach (MDE). As a proof of concept, we illustrate the methodology to produce an UML profile associated with RBAC security pattern. A case study of GPS system is also provided to demonstrate the application of generated profile.
机译:安全性已成为当前软件和系统开发中的重要挑战。大多数设计师都是软件开发专家,而不是安全专家。指导他们决定在软件开发的早期阶段如何以及在何处应用安全机制以减少开发时间和成本很重要。为了实现此目标,我们建议在软件设计阶段将安全专业知识用作安全模式。我们的方法基于组件元模型的使用,以捕获域概念和安全模式以对安全问题的解决方案进行编码。预期结果是将模型作为特定领域的设计解决方案。在这里,我们提倡基于UML概要文件的建模技术,以促进将模式解决方案集成到模型驱动的工程方法(MDE)中。作为概念验证,我们说明了产生与RBAC安全模式相关联的UML概要文件的方法。还提供了GPS系统的案例研究,以演示所生成轮廓的应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号