首页> 外文会议>Information and Communication Technologies, 2006. ICTTA '06. 2nd >UML-Based Representation of Provision-Based Access Control
【24h】

UML-Based Representation of Provision-Based Access Control

机译:基于UML的基于供应的访问控制表示

获取原文

摘要

Lack of security in application development process implies conveyance of responsibility for protection and security from software analyzers and designers to employees developing the system. It imposes extra costs to software projects. To solve this problem, security should be considered in all of the software development phases from requirement engineering to design, implementation, test and maintenance. Access control as one of the security requirements can be gained by provision-based access control (PBAC) enabling authorization systems to decide flexibly and extends the access control mechanism by the employment Of provisional actions but its presented formal definitions are not desirable in a modeling language. In addition, sometimes formal and abstract statements of the PBAC model are too hard for the system developers to understand and cause complications. Even if the security models such as PBAC model are well known, there may be some different comprehensions about them and this causes inconsistent implementation and modeling. Therefore, to facilitate the developer's works, in this paper we represent PBAC concepts using a general purpose visual modeling language, UML, and its functional requirements. To achieve our objectives, our presentation includes static, functional, and dynamic views of the PBAC model. This approach can lead us to reduce the semantic gap between security models and system development
机译:应用程序开发过程中缺乏安全性意味着需要将保护和安全责任从软件分析人员和设计人员传达给开发系统的员工。它给软件项目带来了额外的成本。为了解决这个问题,从需求工程到设计,实施,测试和维护的所有软件开发阶段都应考虑安全性。可通过基于提供的访问控制(PBAC)获得访问控制作为安全要求之一,基于访问的访问控制(PBAC)使授权系统能够灵活地决定并通过采用临时操作来扩展访问控制机制,但是在建模语言中不希望提供其正式的定义。另外,有时候PBAC模型的正式和抽象的陈述对于系统开发人员来说太难理解和引起复杂性了。即使诸如PBAC模型之类的安全模型是众所周知的,对它们的理解也可能有所不同,这会导致实现和建模不一致。因此,为了方便开发人员的工作,在本文中,我们使用通用的可视化建模语言,UML及其功能要求来表示PBAC概念。为了实现我们的目标,我们的演示包括PBAC模型的静态,功能和动态视图。这种方法可以使我们缩小安全模型与系统开发之间的语义鸿沟

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号