Title :
Reusable components for developing security-aware applications
Author :
Probst, Stefan ; Essmayr, Wolfgang ; Weippl, Edgar
Abstract :
Today, security is considered to be an important aspect of multi-tier application development. Thoroughly researched concepts for access control exist and have been proven in mainframe computing. However, they are often not used in today´s development of multi-tier applications. One reason may be the lack of appropriate reusable components that support application developers that frequently have to re-invent the wheel when it comes to access controls. The goal of this paper is to promote awareness of security issues when developing applications and to illustrate a suitable approach for that. Our framework called GAMMA (Generic Authorization Mechanisms for Multi-Tier Applications) offers several authentication, access control, and auditing mechanisms. Access control models can be combined or used simultaneously in order to provide application-specific and highly customizable mechanisms. Moreover, due to its component-based structure, new security models and additional approaches for authentication or auditing can easily be added.
Keywords :
authorisation; security of data; software reusability; GAMMA; access control; auditing; authentication; multi-tier application development; security; security issues; security models; Access control; Application software; Authentication; Authorization; Computer architecture; Connectors; Cryptography; Data security; Software reusability; Wheels;
Conference_Titel :
Computer Security Applications Conference, 2002. Proceedings. 18th Annual
Print_ISBN :
0-7695-1828-1
DOI :
10.1109/CSAC.2002.1176295