• DocumentCode
    3199482
  • Title

    Software Architectural Design Meets Security Engineering

  • Author

    Bode, Stephan ; Fischer, Anja ; Kunhauser, W. ; Riebisch, Matthias

  • Author_Institution
    Tech. Univ. of Ilmenau, Ilmenau
  • fYear
    2009
  • fDate
    14-16 April 2009
  • Firstpage
    109
  • Lastpage
    118
  • Abstract
    Security requirements strongly influence the architectural design of complex IT systems in a similar way as other non-functional requirements. Both security engineering as well as software engineering provide methods to deal with such requirements. However, there is still a critical gap concerning the integration of the methods of these separate fields. In this paper we close this gap with respect to security requirements by proposing a method that combines software engineering approaches with state-of-the-art security engineering principles. This method establishes an explicit alignment between the non-functional goal, the principles in the field of security engineering, and the implementation of a security architecture. The method aims at designing a system´s security architecture based on a small, precisely defined, and application-specific trusted computing base. We illustrate this method by means of a case study which describes distributed enterprise resource planning systems using web services to implement business processes across company boundaries.
  • Keywords
    security of data; software architecture; Web services; business processes; complex IT systems; distributed enterprise resource planning systems; security architecture; security engineering; security requirements; software architectural design; software engineering; Companies; Computer applications; Computer architecture; Design engineering; Design methodology; Enterprise resource planning; Security; Software design; Software engineering; Web services; design method; non-functional requirements; quality attributes; security engineering; security models; security policies; security requirements; software architecture;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Engineering of Computer Based Systems, 2009. ECBS 2009. 16th Annual IEEE International Conference and Workshop on the
  • Conference_Location
    San Francisco, CA
  • Print_ISBN
    978-0-7695-3602-6
  • Type

    conf

  • DOI
    10.1109/ECBS.2009.17
  • Filename
    4839237