首页> 外文期刊>The Journal of object technology >Modeling and ValidatingRole-Based Authorization Policies for aPort Communication System with UML and OCL
【24h】

Modeling and ValidatingRole-Based Authorization Policies for aPort Communication System with UML and OCL

机译:使用UML和OCL的体育通信系统的建模与验证基于角色的授权策略

获取原文
           

摘要

Modern sea or inland ports rely on digital communication and systems to boost rapid turnover of trade. Stakeholders like shippers, shipping lines, container terminals and port authorities collaborate and compete using their own legacy applications. Many sea ports operate Port Community Systems (PCS) to orchestrate processes between the players. These software systems are potential targets of security threats that may lead to payment fraud, espionage of competitors, smuggling, theft, export control violations, up to disasters involving dangerous goods possibly effecting public mains. In our approach we apply modeling to the field of information security. We combine and focus on Role-Based Access Control (RBAC) with constraints and Attribute-Based Access Control (ABAC) for finer grained authorization constraints. In a concrete case study we model authorization policies within port communities that partly utilize dedicated PCS. The purpose is to increase the integrity of exchanged data and thus reduce the risks of attacks or failures. We employ the UML-based Specification Environment (USE) and its OCL support to validate specified security properties for a typical container shipping scenario.
机译:现代海运或内陆港口依靠数字通信和系统来提高贸易的快速营业额。利益相关者喜欢托运人,运输线,集装箱码头和港口当局使用自己的遗留应用程序合作和竞争。许多海港运营港口社区系统(PC)来协调玩家之间的过程。这些软件系统是安全威胁的潜在目标,可能导致支付欺诈,竞争对手,走私,盗窃,出口管制违规行为,涉及可能影响公共电源的灾害的灾害。在我们的方法中,我们将建模应用于信息安全领域。我们结合并专注于基于角色的访问控制(RBAC),其中包含基于约束和基于属性的访问控制(ABAC),用于更精细的粗粒授权约束。在一个具体的案例研究中,我们在部分利用专用PC的港口社区内模拟授权策略。目的是增加交换数据的完整性,从而降低攻击或失败的风险。我们使用基于UML的规范环境(使用)及其OCL支持,以验证典型容器运输方案的指定安全性属性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号