DocumentCode :
2454631
Title :
UML-Based Representation of Provision-Based Access Control
Author :
Farkhani, Toktam Ramezani ; Razzazi, Mohammad Reza
Author_Institution :
CEIT Dept., Amirkabir Univ. of Technol., Tehran
Volume :
2
fYear :
0
fDate :
0-0 0
Firstpage :
3605
Lastpage :
3610
Abstract :
Lack of security in application development process implies conveyance of responsibility for protection and security from software analyzers and designers to employees developing the system. It imposes extra costs to software projects. To solve this problem, security should be considered in all of the software development phases from requirement engineering to design, implementation, test and maintenance. Access control as one of the security requirements can be gained by provision-based access control (PBAC) enabling authorization systems to decide flexibly and extends the access control mechanism by the employment Of provisional actions but its presented formal definitions are not desirable in a modeling language. In addition, sometimes formal and abstract statements of the PBAC model are too hard for the system developers to understand and cause complications. Even if the security models such as PBAC model are well known, there may be some different comprehensions about them and this causes inconsistent implementation and modeling. Therefore, to facilitate the developer´s works, in this paper we represent PBAC concepts using a general purpose visual modeling language, UML, and its functional requirements. To achieve our objectives, our presentation includes static, functional, and dynamic views of the PBAC model. This approach can lead us to reduce the semantic gap between security models and system development
Keywords :
Unified Modeling Language; authorisation; formal specification; UML; application development process; authorization systems; functional requirements; provision-based access control; security models; software analyzers; software development phases; software projects; visual modeling language; Access control; Application software; Costs; Design engineering; Lead; Programming; Protection; Security; Software design; Software testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information and Communication Technologies, 2006. ICTTA '06. 2nd
Conference_Location :
Damascus
Print_ISBN :
0-7803-9521-2
Type :
conf
DOI :
10.1109/ICTTA.2006.1685000
Filename :
1685000
Link To Document :
بازگشت