A Formal Framework for Secure Design and Constraint Checking in UML
A Formal Framework for Secure Design and Constraint Checking in UML
复制标题
UML 中安全设计和约束检查的正式框架
DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
S. Demurjian
中科院分区:
文献类型:
--
作者:
T. Doan;L. Michel;S. Demurjian
The design of software applications using the unified modeling language, UML, embodies an incremental process, transitioning a design from state to state over time. The integration of security into this process is critical to satisfy an application’s security requirements. This paper reports on a formal approach that incorporates role-based access control (RBAC), mandatory access control (MAC), and lifetimes, with constraint checking, into UML for time-sensitive application design. The resulting framework promotes secure software design by tracking an application’s security requirements as UML elements and connections are added, modified, and deleted. It also captures snapshots of each design state by checking constraints on security satisfaction properties for the design. Our objective in this paper is to detail the formal functional model with constraint checking that is able to track security for a UML design via the creation and maintenance of multiple design instances. To demonstrate the feasibility of our efforts, we report on the transition of the functional framework for secure design into Borland’s UML tool Together Control Center.