A Formal Framework for Secure Design and Constraint Checking in UML

A Formal Framework for Secure Design and Constraint Checking in UML
复制标题

UML 中安全设计和约束检查的正式框架

DOI:
--
复制
发表时间:
2006
期刊:
International Symposium on Signals, Systems, and Electronics
影响因子:
--
通讯作者:
S. Demurjian
S. Demurjian
中科院分区:
--
文献类型:
--
作者:
T. Doan;L. Michel;S. Demurjian

文献摘要

被引文献

相似文献

使用统一建模语言UML的软件应用程序设计体现了一个增量过程,随着时间的推移,将设计从一个状态转换到另一个状态。将安全性集成到此流程中对于满足应用程序的安全要求至关重要。本文报告了一种正式的方法,结合基于角色的访问控制(RBAC),强制访问控制(MAC),和生命周期,约束检查,到UML的时间敏感的应用程序设计。由此产生的框架,促进安全的软件设计,通过跟踪一个应用程序的安全需求,作为UML元素和连接的添加,修改和删除。它还通过检查设计的安全性满足属性的约束来捕获每个设计状态的快照。在本文中,我们的目标是详细的正式功能模型与约束检查,能够跟踪安全的UML设计,通过创建和维护多个设计实例。为了证明我们的努力的可行性,我们报告的过渡到Borland的UML工具一起控制中心的安全设计的功能框架。
The design of software applications using the unified modeling language, UML, embodies an incremental process, transitioning a design from state to state over time. The integration of security into this process is critical to satisfy an application’s security requirements. This paper reports on a formal approach that incorporates role-based access control (RBAC), mandatory access control (MAC), and lifetimes, with constraint checking, into UML for time-sensitive application design. The resulting framework promotes secure software design by tracking an application’s security requirements as UML elements and connections are added, modified, and deleted. It also captures snapshots of each design state by checking constraints on security satisfaction properties for the design. Our objective in this paper is to detail the formal functional model with constraint checking that is able to track security for a UML design via the creation and maintenance of multiple design instances. To demonstrate the feasibility of our efforts, we report on the transition of the functional framework for secure design into Borland’s UML tool Together Control Center.