System modeling plays an important role in software development. UML modeling is based on the re-quirements,in which the safety is not considered fully. Taking a hospital information system as an example,the general structure of the hospital internal is described clearly through the use case diagram,and the security of medi-cal record subsystem of hospital information system is analyzed. According to the existing problems,the hospital in-formation system security model with a combination of XACML and VPL is achieved.%系统建模是软件开发的前提。 UML 是根据需求建模,但是安全性没有考虑充分。现以医院信息系统为例,首先通过用例图清晰描述出医院内部的总体结构;然后对医院信息系统的病历子系统进行了安全性方面的分析;最后根据存在的问题,在 UML 建模的基础上,结合可扩展的访问控制建模语言 XACML 及视图策略语言 VPL 相关元素,实现软件系统安全建模。
展开▼