• DocumentCode
    2967383
  • Title

    An extended object-oriented security model for high secure office environments

  • Author

    Guan, Boo-Chyuan ; Wang, Ping ; Chen, Sheng-Jyh ; Chang, Ray-I

  • Author_Institution
    Center of Inf. Manage., Chung Shan Inst. of Sci. & Technol., Lung-Tan, Taiwan
  • fYear
    2003
  • fDate
    14-16 Oct. 2003
  • Firstpage
    57
  • Lastpage
    61
  • Abstract
    In [S. Castano et al. (1992)], an object-oriented security model was proposed to protect documents in office environments. It defined role as a set of actions and responsibilities played by users to identify the operations that they can execute on documents. This scheme can make representation and realization easy while using modem object-oriented programming languages to model an information system. However, it simply considered the authorization of operation from an identified role to the document. The available time slot associated with this operation was not addressed. Moreover, actions and responsibilities to the access authorization of a peripheral device (such as the printer) were not specified. These characteristics are very important for a high-secure system in military or government that must protect information of different classifications against unauthorized access. After adoption of the UML 1.1 specification by the OMG membership in November 1997, Unified Modeling Language (UML) has been widely accepted as an object oriented software analysis/design methodology in the software engineering community. It provides most of the concepts and notations that are essential for documenting object oriented models. To demonstrate our approach, we have formulated security models for high secure office systems using the UML model.
  • Keywords
    authorisation; data privacy; document handling; object-oriented methods; object-oriented programming; office environment; specification languages; UML 1.1 specification; Unified Modeling Language; information system; object oriented software analysis; object-oriented programming language; object-oriented security model; office environment; peripheral device; software engineering; unauthorized access; Authorization; Government; Information security; Information systems; Modems; Object oriented modeling; Object oriented programming; Printers; Protection; Unified modeling language;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology, 2003. Proceedings. IEEE 37th Annual 2003 International Carnahan Conference on
  • Print_ISBN
    0-7803-7882-2
  • Type

    conf

  • DOI
    10.1109/CCST.2003.1297535
  • Filename
    1297535