• DocumentCode
    3179169
  • Title

    The use of system security description method in security design assement: A case study

  • Author

    Maeda, Tsukasa ; Kurihara, Masahito

  • Author_Institution
    Grad. Sch. of Inf. Sci. & Technol., Hokkaido Univ., Sapporo, Japan
  • fYear
    2010
  • fDate
    10-13 Oct. 2010
  • Firstpage
    350
  • Lastpage
    357
  • Abstract
    In this paper, we demonstrate through a case study the effectiveness of a description method that we developed as a system analysis tool to describe the structure of the security of systems. We apply the description method in design assessment of a digital right management system which has to meet complex security requirements. This method, based on the assumption of the use of standard encryption technologies and existing cryptographic protocols, reveals hidden security threats and vulnerabilities of systems. It extracts only security elements that constitute the trust relationship of system components, describing the relation between the elements, and analyzing the relation. This method provides a valuable assistance tool for frontline engineers in system development fields to build secure systems, and an efficient communication paradigm between stakeholders of a system to help them in understanding the security of the system and confirming that their security requirements are fulfilled.
  • Keywords
    cryptographic protocols; digital rights management; systems analysis; cryptographic protocols; digital right management system; encryption technologies; security design assessment; system analysis; system security description method; Cryptography; authentication; system description; system security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems Man and Cybernetics (SMC), 2010 IEEE International Conference on
  • Conference_Location
    Istanbul
  • ISSN
    1062-922X
  • Print_ISBN
    978-1-4244-6586-6
  • Type

    conf

  • DOI
    10.1109/ICSMC.2010.5641807
  • Filename
    5641807