首页> 外文会议>22nd International Conference on Conceptual Modeling; Oct 13-16, 2003; Chicago, IL, USA >Requirement Engineering Meets Security: A Case Study on Modelling Secure Electronic Transactions by VISA and Mastercard
【24h】

Requirement Engineering Meets Security: A Case Study on Modelling Secure Electronic Transactions by VISA and Mastercard

机译:需求工程满足安全性:VISA和万事达卡对安全电子交易进行建模的案例研究

获取原文
获取原文并翻译 | 示例

摘要

Computer Security is one of today's hot topic and the need for conceptual models of security features have brought up a number of proposals ranging from UML extensions to novel conceptual models. What is still missing, however, are models that focus on high-level security requirements, without forcing the modeler to immediately get down to security mechanisms. The modeling process itself should make it clear why encryption, authentication or access control are necessary, and what are the tradeoffs, if they are selected. In this paper we show that the i~*/Tropos framework lacks the ability to capture these essential features and needs to be augmented. To motivate our proposal, we build upon a substantial case study - the modeling of the Secure Electronic Transactions e-commerce suites by VISA and MasterCard - to identify missing modeling features. In a nutshell, the key missing concept is the separation of the notion of offering a service (of a handling data, performing a task or fulfilling a goal) and ownership of the very same service. This separation is what makes security essential. The ability of the methodology to model a clear dependency relation between those offering a service (the merchant processing a credit card number), those requesting the service (the bank debiting the payment), and those owning the very same data (the cardholder), make security solutions emerge as a natural consequence of the modeling process.
机译:计算机安全是当今的热门话题之一,对安全功能概念模型的需求提出了许多建议,从UML扩展到新颖的概念模型。但是,仍然缺少专注于高级别安全性要求的模型,而没有强迫建模者立即采用安全性机制。建模过程本身应明确说明为什么需要加密,身份验证或访问控制,以及如果选择了哪些折衷方案,则该作何选择。在本文中,我们表明i〜* / Tropos框架缺乏捕获这些基本功能的能力,需要加以增强。为了激发我们的建议,我们以大量案例研究为基础-通过VISA和万事达卡对安全电子交易电子商务套件进行建模-以确定缺少的建模功能。简而言之,关键的缺失概念是将提供服务(处理数据,执行任务或实现目标)的概念与相同服务的所有权分开。这种分离使安全至关重要。该方法能够在提供服务的人(处理信用卡号码的商人),请求服务的人(银行从付款中扣除)和拥有完全相同的数据的人(持卡人)之间建立清晰的依赖关系模型,使安全解决方案成为建模过程的自然结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号