Title :
Software Architectural Design Meets Security Engineering
Author :
Bode, Stephan ; Fischer, Anja ; Kunhauser, W. ; Riebisch, Matthias
Author_Institution :
Tech. Univ. of Ilmenau, Ilmenau
Abstract :
Security requirements strongly influence the architectural design of complex IT systems in a similar way as other non-functional requirements. Both security engineering as well as software engineering provide methods to deal with such requirements. However, there is still a critical gap concerning the integration of the methods of these separate fields. In this paper we close this gap with respect to security requirements by proposing a method that combines software engineering approaches with state-of-the-art security engineering principles. This method establishes an explicit alignment between the non-functional goal, the principles in the field of security engineering, and the implementation of a security architecture. The method aims at designing a system´s security architecture based on a small, precisely defined, and application-specific trusted computing base. We illustrate this method by means of a case study which describes distributed enterprise resource planning systems using web services to implement business processes across company boundaries.
Keywords :
security of data; software architecture; Web services; business processes; complex IT systems; distributed enterprise resource planning systems; security architecture; security engineering; security requirements; software architectural design; software engineering; Companies; Computer applications; Computer architecture; Design engineering; Design methodology; Enterprise resource planning; Security; Software design; Software engineering; Web services; design method; non-functional requirements; quality attributes; security engineering; security models; security policies; security requirements; software architecture;
Conference_Titel :
Engineering of Computer Based Systems, 2009. ECBS 2009. 16th Annual IEEE International Conference and Workshop on the
Conference_Location :
San Francisco, CA
Print_ISBN :
978-0-7695-3602-6
DOI :
10.1109/ECBS.2009.17