首页> 外文会议>European Symposium on Research in Computer Security; 20050912-14; Milan(IT) >Specification and Validation of Authorisation Constraints Using UML and OCL
【24h】

Specification and Validation of Authorisation Constraints Using UML and OCL

机译:使用UML和OCL的授权约束的规范和验证

获取原文
获取原文并翻译 | 示例

摘要

Authorisation constraints can help the policy architect design and express higher-level security policies for organisations such as financial institutes or governmental agencies. Although the importance of constraints has been addressed in the literature, there does not exist a systematic way to validate and test authorisation constraints. In this paper, we attempt to specify non-temporal constraints and history-based constraints in Object Constraint Language (OCL) which is a constraint specification language of Unified Modeling Language (UML) and describe how we can facilitate the USE tool to validate and test such policies. We also discuss the issues of identification of conflicting constraints and missing constraints.
机译:授权约束可以帮助策略设计者设计和表达针对金融机构或政府机构等组织的更高级别的安全策略。尽管在文献中已经解决了约束的重要性,但是还没有一种系统的方法来验证和测试授权约束。在本文中,我们尝试在对象约束语言(OCL)中指定非时间约束和基于历史的约束,对象约束语言是统一建模语言(UML)的约束规范语言,并描述了如何帮助USE工具进行验证和测试这样的政策。我们还将讨论识别冲突约束和缺失约束的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号