• DocumentCode
    1487879
  • Title

    Constructing Authorization Systems Using Assurance Management Framework

  • Author

    Hu, Hongxin ; Ahn, Gail-Joon

  • Author_Institution
    Security Eng. for Future Comput. Lab., Arizona State Univ., Tempe, AZ, USA
  • Volume
    40
  • Issue
    4
  • fYear
    2010
  • fDate
    7/1/2010 12:00:00 AM
  • Firstpage
    396
  • Lastpage
    405
  • Abstract
    Model-driven approach has recently received much attention in developing secure software and systems. In addition, software developers have attempted to employ such an emerging approach in the early stage of software development life cycle. However, security concerns are rarely considered and practiced due to the lack of appropriate systematic mechanisms and tools. In this paper, we introduce a multilayered software development life cycle (SDLC), which is based on an assurance management framework (AMF), focusing on the development of authorization systems. AMF facilitates comprehensive realization of formal security model, security policy specification and verification, generation of security enforcement codes, and rigorous conformance testing. We also articulate our experience in analyzing role-based authorization requirements and realizing those requirements in constructing a role-based authorization system.
  • Keywords
    authorisation; software engineering; assurance management framework; conformance testing; formal security model; model-driven approach; multilayered software development life cycle; role-based authorization system; security enforcement code generation; security policy specification; software security; Authorization; model-driven approach; role based; unified modeling language (UML);
  • fLanguage
    English
  • Journal_Title
    Systems, Man, and Cybernetics, Part C: Applications and Reviews, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1094-6977
  • Type

    jour

  • DOI
    10.1109/TSMCC.2010.2047856
  • Filename
    5462923