{"id":{"repo_id":"freiburg-diss","oai_identifier":"oai:freidok.uni-freiburg.de:1253"},"canonical_url":"https://search.dev.ndltd.org/etd/freiburg-diss/oai:freidok.uni-freiburg.de:1253","repository":{"repo_id":"freiburg-diss","name":"University of Freiburg","base_url":"https://freidok.uni-freiburg.de/oai/oai2.php"},"display":{"title":"Model driven security from UML models to access control architectures","abstract":"We present a new approach to building secure systems. In our approach, which we call Model Driven Security, designers specify system models along with their security requirements and use tools to automatically generate system architectures from the models including complete, configured security infrastructures. In that way, Model Driven Security helps to tightly integrate <br>security into the software development process. As a result, our approach can <br>be used to improve both the productivity of the developers of secure software <br>systems and the quality of the resulting systems. <br> <br>Rather than fixing one particular modeling language for this process, we propose a schema for constructing such languages that combines languages for modeling systems with languages for modeling security. Thus the schema allows language designers to leverage expert know-how that is required to define a modeling language for a particular area as well as accompanying methods and tools. <br> <br>We present different instances of this schema, which combine different <br>UML modeling languages with a security modeling language for formalizing <br>access control requirements. From models in these languages, we automatically <br>generate access control architectures for distributed applications. The <br>modeling languages and generation process are semantically well-founded and <br>are based on an extension of role-based access control. We have implemented <br>this approach in a prototypical tool that we used to conduct a case study <br>and report on experiences.","abstract_html":"We present a new approach to building secure systems. In our approach, which we call Model Driven Security, designers specify system models along with their security requirements and use tools to automatically generate system architectures from the models including complete, configured security infrastructures. In that way, Model Driven Security helps to tightly integrate &lt;br&gt;security into the software development process. As a result, our approach can &lt;br&gt;be used to improve both the productivity of the developers of secure software &lt;br&gt;systems and the quality of the resulting systems. &lt;br&gt; &lt;br&gt;Rather than fixing one particular modeling language for this process, we propose a schema for constructing such languages that combines languages for modeling systems with languages for modeling security. Thus the schema allows language designers to leverage expert know-how that is required to define a modeling language for a particular area as well as accompanying methods and tools. &lt;br&gt; &lt;br&gt;We present different instances of this schema, which combine different &lt;br&gt;UML modeling languages with a security modeling language for formalizing &lt;br&gt;access control requirements. From models in these languages, we automatically &lt;br&gt;generate access control architectures for distributed applications. The &lt;br&gt;modeling languages and generation process are semantically well-founded and &lt;br&gt;are based on an extension of role-based access control. We have implemented &lt;br&gt;this approach in a prototypical tool that we used to conduct a case study &lt;br&gt;and report on experiences.","abstract_has_math":false,"creators":["Lodderstedt, Torsten"],"institution":null,"degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Basin, David"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":null,"date_issued":"","date_published":null,"updated_at":"2026-07-24T02:22:10Z","subjects":["Modellierungssprachen","Softwareentwicklungswerkzeuge","Metamodellierung","security engineering","meta modeling","modeling languages"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://freidok.uni-freiburg.de/data/1253","outbound_label":"Repository record","outbound_source":"source_url"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Basin, David"]},{"key":"dc:creator","label":"Author","values":["Lodderstedt, Torsten"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:type","label":"Dc Type","values":["DoctoralThesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Modellierungssprachen","Softwareentwicklungswerkzeuge","Metamodellierung","security engineering","meta modeling","modeling languages"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["We present a new approach to building secure systems. In our approach, which we call Model Driven Security, designers specify system models along with their security requirements and use tools to automatically generate system architectures from the models including complete, configured security infrastructures. In that way, Model Driven Security helps to tightly integrate <br>security into the software development process. As a result, our approach can <br>be used to improve both the productivity of the developers of secure software <br>systems and the quality of the resulting systems. <br> <br>Rather than fixing one particular modeling language for this process, we propose a schema for constructing such languages that combines languages for modeling systems with languages for modeling security. Thus the schema allows language designers to leverage expert know-how that is required to define a modeling language for a particular area as well as accompanying methods and tools. <br> <br>We present different instances of this schema, which combine different <br>UML modeling languages with a security modeling language for formalizing <br>access control requirements. From models in these languages, we automatically <br>generate access control architectures for distributed applications. The <br>modeling languages and generation process are semantically well-founded and <br>are based on an extension of role-based access control. We have implemented <br>this approach in a prototypical tool that we used to conduct a case study <br>and report on experiences.","Wir schlagen eine neue Methode zur Entwicklung sicherer Software-Systeme vor. Die Kernidee unserer Methode, die wir Model Driven Security nennen, ist, daß Softwaredesigner IT-Systeme in Modellen spezifizieren, welche auch die gewünschten Sicherheitseigenschaften des Systems beschreiben. Basierend auf diesen Modellen werden dann mit Hilfe von Werkzeugen Systemarchitekturen mit <br>kompletten und vollständig konfigurierten Sicherheitsmechanismen generiert. <br>Auf diese Weise ermöglicht Model Driven Security die enge Integration von Sicherheit in den Entwicklungsprozess. Unsere Methode kann daher verwendet werden, um die Produktivität bei der Entwicklung von sicheren Softwaresystemen zu erhöhen und die Qualität der resultierenden Systeme zu verbessern. <br> <br>Anstatt eine einzige Modellierungssprache für diesen Prozeß vorzugeben, schlagen wir ein Schema für die Definition solcher Sprachen vor, in welchem Sprachen für die Systemmodellierung mit solchen für die Modellierung von Sicherheitseigenschaften kombiniert werden. <br> <br>Wir präsentieren verschiedene Beispiele für die Anwendung dieses Schemas, in welchen UML-basierte Modellierungssprachen mit einer Sprache für die Spezifikation von Zugriffskontrollmodellen kombiniert werden. Wir zeigen außerdem, wie auf der Basis von Modellen in diesen Sprachen Zugriffskontrollarchitekturen für verteilte Systeme generiert werden können. Die Modellierungssprachen und der Generierungsprozess sind semantisch wohl fundiert und basieren auf einer Erweiterung von rollenbasierter Zugriffskontrolle. Wir haben unsere Methode in einem Werkzeug implementiert, welches wir im Rahmen einer Fallstudie angewendet haben, und wir berichten von unseren Erfahrungen."]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Model driven security from UML models to access control architectures","Modellgetriebene Sicherheit: von UML-Modellen zu Zugriffskontrollarchitekturen"]}]}],"canonical_facts":{"dc:contributor":["Basin, David"],"dc:creator":["Lodderstedt, Torsten"],"dc:description.abstract":["We present a new approach to building secure systems. In our approach, which we call Model Driven Security, designers specify system models along with their security requirements and use tools to automatically generate system architectures from the models including complete, configured security infrastructures. In that way, Model Driven Security helps to tightly integrate <br>security into the software development process. As a result, our approach can <br>be used to improve both the productivity of the developers of secure software <br>systems and the quality of the resulting systems. <br> <br>Rather than fixing one particular modeling language for this process, we propose a schema for constructing such languages that combines languages for modeling systems with languages for modeling security. Thus the schema allows language designers to leverage expert know-how that is required to define a modeling language for a particular area as well as accompanying methods and tools. <br> <br>We present different instances of this schema, which combine different <br>UML modeling languages with a security modeling language for formalizing <br>access control requirements. From models in these languages, we automatically <br>generate access control architectures for distributed applications. The <br>modeling languages and generation process are semantically well-founded and <br>are based on an extension of role-based access control. We have implemented <br>this approach in a prototypical tool that we used to conduct a case study <br>and report on experiences.","Wir schlagen eine neue Methode zur Entwicklung sicherer Software-Systeme vor. Die Kernidee unserer Methode, die wir Model Driven Security nennen, ist, daß Softwaredesigner IT-Systeme in Modellen spezifizieren, welche auch die gewünschten Sicherheitseigenschaften des Systems beschreiben. Basierend auf diesen Modellen werden dann mit Hilfe von Werkzeugen Systemarchitekturen mit <br>kompletten und vollständig konfigurierten Sicherheitsmechanismen generiert. <br>Auf diese Weise ermöglicht Model Driven Security die enge Integration von Sicherheit in den Entwicklungsprozess. Unsere Methode kann daher verwendet werden, um die Produktivität bei der Entwicklung von sicheren Softwaresystemen zu erhöhen und die Qualität der resultierenden Systeme zu verbessern. <br> <br>Anstatt eine einzige Modellierungssprache für diesen Prozeß vorzugeben, schlagen wir ein Schema für die Definition solcher Sprachen vor, in welchem Sprachen für die Systemmodellierung mit solchen für die Modellierung von Sicherheitseigenschaften kombiniert werden. <br> <br>Wir präsentieren verschiedene Beispiele für die Anwendung dieses Schemas, in welchen UML-basierte Modellierungssprachen mit einer Sprache für die Spezifikation von Zugriffskontrollmodellen kombiniert werden. Wir zeigen außerdem, wie auf der Basis von Modellen in diesen Sprachen Zugriffskontrollarchitekturen für verteilte Systeme generiert werden können. Die Modellierungssprachen und der Generierungsprozess sind semantisch wohl fundiert und basieren auf einer Erweiterung von rollenbasierter Zugriffskontrolle. Wir haben unsere Methode in einem Werkzeug implementiert, welches wir im Rahmen einer Fallstudie angewendet haben, und wir berichten von unseren Erfahrungen."],"dc:format.medium":["application/pdf"],"dc:subject":["Modellierungssprachen","Softwareentwicklungswerkzeuge","Metamodellierung","security engineering","meta modeling","modeling languages"],"dc:title":["Model driven security from UML models to access control architectures","Modellgetriebene Sicherheit: von UML-Modellen zu Zugriffskontrollarchitekturen"],"dc:type":["DoctoralThesis"]},"updated_at":"2026-07-24T02:22:10Z"}