DocumentCode
2967383
Title
An extended object-oriented security model for high secure office environments
Author
Guan, Boo-Chyuan ; Wang, Ping ; Chen, Sheng-Jyh ; Chang, Ray-I
Author_Institution
Center of Inf. Manage., Chung Shan Inst. of Sci. & Technol., Lung-Tan, Taiwan
fYear
2003
fDate
14-16 Oct. 2003
Firstpage
57
Lastpage
61
Abstract
In [S. Castano et al. (1992)], an object-oriented security model was proposed to protect documents in office environments. It defined role as a set of actions and responsibilities played by users to identify the operations that they can execute on documents. This scheme can make representation and realization easy while using modem object-oriented programming languages to model an information system. However, it simply considered the authorization of operation from an identified role to the document. The available time slot associated with this operation was not addressed. Moreover, actions and responsibilities to the access authorization of a peripheral device (such as the printer) were not specified. These characteristics are very important for a high-secure system in military or government that must protect information of different classifications against unauthorized access. After adoption of the UML 1.1 specification by the OMG membership in November 1997, Unified Modeling Language (UML) has been widely accepted as an object oriented software analysis/design methodology in the software engineering community. It provides most of the concepts and notations that are essential for documenting object oriented models. To demonstrate our approach, we have formulated security models for high secure office systems using the UML model.
Keywords
authorisation; data privacy; document handling; object-oriented methods; object-oriented programming; office environment; specification languages; UML 1.1 specification; Unified Modeling Language; information system; object oriented software analysis; object-oriented programming language; object-oriented security model; office environment; peripheral device; software engineering; unauthorized access; Authorization; Government; Information security; Information systems; Modems; Object oriented modeling; Object oriented programming; Printers; Protection; Unified modeling language;
fLanguage
English
Publisher
ieee
Conference_Titel
Security Technology, 2003. Proceedings. IEEE 37th Annual 2003 International Carnahan Conference on
Print_ISBN
0-7803-7882-2
Type
conf
DOI
10.1109/CCST.2003.1297535
Filename
1297535
Link To Document