Authors:
Farid Mehr
and
Ulf Schreier
Affiliation:
Faculty of Information Systems, Furtwangen University, Germany
Keyword(s):
UML Security, Security Modelling, Security Design, Security Integration, Secure Software Engineering, SOA Security, Model-Driven Security.
Related
Ontology
Subjects/Areas/Topics:
Enterprise Information Systems
;
Formal Methods
;
Information Systems Analysis and Specification
;
Methodologies and Technologies
;
Modeling Formalisms, Languages and Notations
;
Modeling of Distributed Systems
;
Operational Research
;
Security
;
Simulation and Modeling
Abstract:
Service oriented computing is increasingly accepted as a cross-disciplinary paradigm to integrate distributed application functionality through service interfaces. Integration through services as entry points for inter-organisational collaboration can be achieved by exchanging data in messages. In this architectural style, the security of sensitive exchanged data is essential. Security needs to be carefully considered during the entire
life-cycle (Devanbu, 2000). Unfortunately, current UML-based modelling approaches do not support the adequate integration of message security concerns. In this paper, we investigate various integration options with UML systematically. The evaluation encompasses most of the options that are proposed today in science and industry as UML profiles. We conclude that neither of those approaches is sufficient for the systematic and comprehensive treatment of message security during modelling. To this end, we propose a new approach that is based on UML and v
ery minor extensions of OCL.
(More)