DocumentCode :
2967383
Title :
An extended object-oriented security model for high secure office environments
Author :
Guan, Boo-Chyuan ; Wang, Ping ; Chen, Sheng-Jyh ; Chang, Ray-I
Author_Institution :
Center of Inf. Manage., Chung Shan Inst. of Sci. & Technol., Lung-Tan, Taiwan
fYear :
2003
fDate :
14-16 Oct. 2003
Firstpage :
57
Lastpage :
61
Abstract :
In [S. Castano et al. (1992)], an object-oriented security model was proposed to protect documents in office environments. It defined role as a set of actions and responsibilities played by users to identify the operations that they can execute on documents. This scheme can make representation and realization easy while using modem object-oriented programming languages to model an information system. However, it simply considered the authorization of operation from an identified role to the document. The available time slot associated with this operation was not addressed. Moreover, actions and responsibilities to the access authorization of a peripheral device (such as the printer) were not specified. These characteristics are very important for a high-secure system in military or government that must protect information of different classifications against unauthorized access. After adoption of the UML 1.1 specification by the OMG membership in November 1997, Unified Modeling Language (UML) has been widely accepted as an object oriented software analysis/design methodology in the software engineering community. It provides most of the concepts and notations that are essential for documenting object oriented models. To demonstrate our approach, we have formulated security models for high secure office systems using the UML model.
Keywords :
authorisation; data privacy; document handling; object-oriented methods; object-oriented programming; office environment; specification languages; UML 1.1 specification; Unified Modeling Language; information system; object oriented software analysis; object-oriented programming language; object-oriented security model; office environment; peripheral device; software engineering; unauthorized access; Authorization; Government; Information security; Information systems; Modems; Object oriented modeling; Object oriented programming; Printers; Protection; Unified modeling language;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security Technology, 2003. Proceedings. IEEE 37th Annual 2003 International Carnahan Conference on
Print_ISBN :
0-7803-7882-2
Type :
conf
DOI :
10.1109/CCST.2003.1297535
Filename :
1297535
Link To Document :
بازگشت