首页> 外文期刊>Systems, Man, and Cybernetics, Part C: Applications and Reviews, IEEE Transactions on >Constructing Authorization Systems Using Assurance Management Framework
【24h】

Constructing Authorization Systems Using Assurance Management Framework

机译:使用保证管理框架构建授权系统

获取原文
获取原文并翻译 | 示例

摘要

Model-driven approach has recently received much attention in developing secure software and systems. In addition, software developers have attempted to employ such an emerging approach in the early stage of software development life cycle. However, security concerns are rarely considered and practiced due to the lack of appropriate systematic mechanisms and tools. In this paper, we introduce a multilayered software development life cycle (SDLC), which is based on an assurance management framework (AMF), focusing on the development of authorization systems. AMF facilitates comprehensive realization of formal security model, security policy specification and verification, generation of security enforcement codes, and rigorous conformance testing. We also articulate our experience in analyzing role-based authorization requirements and realizing those requirements in constructing a role-based authorization system.
机译:在开发安全的软件和系统中,模型驱动的方法最近受到了广泛的关注。此外,软件开发人员已尝试在软件开发生命周期的早期阶段采用这种新兴方法。但是,由于缺乏适当的系统机制和工具,很少考虑和实践安全性问题。在本文中,我们介绍了一个基于保证管理框架(AMF)的多层软件开发生命周期(SDLC),重点是授权系统的开发。 AMF有助于全面实现正式的安全模型,安全策略规范和验证,安全实施代码的生成以及严格的一致性测试。我们还阐述了我们在分析基于角色的授权需求并在构建基于角色的授权系统时实现这些需求的经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号