DocumentCode
2097467
Title
Model driven security: unification of authorization models for fine-grain access control
Author
Burt, Carol C. ; Bryant, Barrett R. ; Raje, Rajeev R. ; Olson, Andrew ; Auguston, Mikhail
Author_Institution
Alabama Univ., Birmingham, AL, USA
fYear
2003
fDate
16-19 Sept. 2003
Firstpage
159
Lastpage
171
Abstract
The research vision of the Unified Component Meta Model Framework (Uniframe) is to develop infrastructure for components that enables a plug and play component environment where the security contracts are a part of the component description and the security aware middleware is generated by the component integration toolkits. That is, the component providers will define security contracts in addition to the functional contracts. These security contracts will be used to analyze the ability of a service to meet the security constraints when used in a composition of components. A difficulty in progressing the security related aspects of this infrastructure is the lack of a unified access control model that can be leveraged to identify protected resources and access control points at the model level. Existing component technologies utilize various mechanisms for specifying security constraints. This paper will explore issues related to expressing access control requirements of components and the resources they manage. It proposes a platform independent model (PIM) for the access control that can be leveraged to parameterize domain models. It also outlines the analysis necessary to progress a standard transformation from this PIM to three existing platform specific models (PSMs).
Keywords
authorisation; distributed object management; middleware; object-oriented programming; quality of service; security of data; PIM; PSM; Unified Component Meta Model Framework Uniframe; access control model; access control points; access control requirements; authorization models; component integration toolkits; component technologies; components providers; distributed system software; domain models; fine-grain access control; functional contracts; model driven security; platform independent model; platform specific models; protected resources; quality of service; security aware middleware; security constraints; security contracts; standard transformation; Access control; Authorization; Business communication; Collaborative software; Contracts; IEC standards; ISO standards; Middleware; Quality of service; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Enterprise Distributed Object Computing Conference, 2003. Proceedings. Seventh IEEE International
Print_ISBN
0-7695-1994-6
Type
conf
DOI
10.1109/EDOC.2003.1233846
Filename
1233846
Link To Document