Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
Model driven security: from UML models to access control infrastructures
Basin D., Doser J., Lodderstedt T. ACM Transactions on Software Engineering and Methodology15 (1):39-91,2006.Type:Article
Date Reviewed: Jul 5 2006

Are you tired of the lengthy encoding of your access control policies in your favorite realization technology? If so, the work presented in this paper may be very interesting to you. The authors demonstrate the benefits of the model-driven development approach for access control policies: users specify only six roles and 60 permissions in the security model instead of 5,000 lines of Extensible Markup Language (XML) code (plus an additional 2,000 lines of Java code if you use Enterprise JavaBeans (EJBs)). In addition, the specification is platform independent, and thus can be mapped to either an EJB or a C# environment.

The authors present a generic concept for systematically extending modeling languages that provides a unified modeling language (UML)-compatible meta-model, a UML-compatible concrete syntax, and an explicit notion of users to enable the modeling of control access policies. The required integration at the meta-model, concrete! syntax, and semantics levels is outlined for a simple modeling language. The authors describe how the specified control access policy model can, in a subsequent step, be used to generate, for specific platforms such as EJB or C#, the configuration data that realizes the most basic access constraints, as well as additional code fragments that check, at the entrance of methods, whether access should be granted.

Reviewer:  Holger Giese Review #: CR133023 (0705-0474)
Bookmark and Share
 
Languages (D.2.1 ... )
 
 
Object-Oriented Design Methods (D.2.2 ... )
 
 
Tools (D.2.1 ... )
 
 
Design Tools and Techniques (D.2.2 )
 
 
Requirements/ Specifications (D.2.1 )
 
 
Security and Protection (K.6.5 )
 
Would you recommend this review?
yes
no
Other reviews under "Languages": Date
An examination of requirements specification languages
Tse T., Pong L. The Computer Journal 34(2): 143-152, 1991. Type: Article
Apr 1 1992
Towards a formal basis for the formal development method and the Ina Jo specification language
Berry D. IEEE Transactions on Software Engineering SE-13(2): 184-201, 1987. Type: Article
Oct 1 1987
On the design of ANNA, a specification language for ADA
Luckham D.  Software validation: inspection-testing-verification-alternatives (, Darmstadt, West Germany,2271984. Type: Proceedings
May 1 1986
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy