• DocumentCode
    2097467
  • Title

    Model driven security: unification of authorization models for fine-grain access control

  • Author

    Burt, Carol C. ; Bryant, Barrett R. ; Raje, Rajeev R. ; Olson, Andrew ; Auguston, Mikhail

  • Author_Institution
    Alabama Univ., Birmingham, AL, USA
  • fYear
    2003
  • fDate
    16-19 Sept. 2003
  • Firstpage
    159
  • Lastpage
    171
  • Abstract
    The research vision of the Unified Component Meta Model Framework (Uniframe) is to develop infrastructure for components that enables a plug and play component environment where the security contracts are a part of the component description and the security aware middleware is generated by the component integration toolkits. That is, the component providers will define security contracts in addition to the functional contracts. These security contracts will be used to analyze the ability of a service to meet the security constraints when used in a composition of components. A difficulty in progressing the security related aspects of this infrastructure is the lack of a unified access control model that can be leveraged to identify protected resources and access control points at the model level. Existing component technologies utilize various mechanisms for specifying security constraints. This paper will explore issues related to expressing access control requirements of components and the resources they manage. It proposes a platform independent model (PIM) for the access control that can be leveraged to parameterize domain models. It also outlines the analysis necessary to progress a standard transformation from this PIM to three existing platform specific models (PSMs).
  • Keywords
    authorisation; distributed object management; middleware; object-oriented programming; quality of service; security of data; PIM; PSM; Unified Component Meta Model Framework Uniframe; access control model; access control points; access control requirements; authorization models; component integration toolkits; component technologies; components providers; distributed system software; domain models; fine-grain access control; functional contracts; model driven security; platform independent model; platform specific models; protected resources; quality of service; security aware middleware; security constraints; security contracts; standard transformation; Access control; Authorization; Business communication; Collaborative software; Contracts; IEC standards; ISO standards; Middleware; Quality of service; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Enterprise Distributed Object Computing Conference, 2003. Proceedings. Seventh IEEE International
  • Print_ISBN
    0-7695-1994-6
  • Type

    conf

  • DOI
    10.1109/EDOC.2003.1233846
  • Filename
    1233846