Back to results

University of Freiburg

Model driven security from UML models to access control architectures

Abstract

dc:description.abstract

We present a new approach to building secure systems. In our approach, which we call Model Driven Security, designers specify system models along with their security requirements and use tools to automatically generate system architectures from the models including complete, configured security infrastructures. In that way, Model Driven Security helps to tightly integrate <br>security into the software development process. As a result, our approach can <br>be used to improve both the productivity of the developers of secure software <br>systems and the quality of the resulting systems. <br> <br>Rather than fixing one particular modeling language for this process, we propose a schema for constructing such languages that combines languages for modeling systems with languages for modeling security. Thus the schema allows language designers to leverage expert know-how that is required to define a modeling language for a particular area as well as accompanying methods and tools. <br> <br>We present different instances of this schema, which combine different <br>UML modeling languages with a security modeling language for formalizing <br>access control requirements. From models in these languages, we automatically <br>generate access control architectures for distributed applications. The <br>modeling languages and generation process are semantically well-founded and <br>are based on an extension of role-based access control. We have implemented <br>this approach in a prototypical tool that we used to conduct a case study <br>and report on experiences.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Lodderstedt, Torsten
Contributors dc:contributor
  • Basin, David

Subjects

dc:subject × 6

Identifiers

dc:identifier.*
Repository record source_url
https://freidok.uni-freiburg.de/data/1253
OAI identifier oai:identifier
oai:freidok.uni-freiburg.de:1253

Chain of custody

source
Harvested from
University of Freiburg
Base URL
freidok.uni-freiburg.de/oai/oai2.php
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Lodderstedt, Torsten. Model driven security from UML models to access control architectures. https://freidok.uni-freiburg.de/data/1253