首页> 外文OA文献 >Requirement Engineering meets Security: A Case Study on Modelling Secure Electronic Transactions by VISA and Mastercard
【2h】

Requirement Engineering meets Security: A Case Study on Modelling Secure Electronic Transactions by VISA and Mastercard

机译:需求工程满足安全性:VISA和万事达卡对安全电子交易进行建模的案例研究

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Computer Security is one of today's hot topic and the need for conceptual models of security features have brought up a number of proposals ranging from UML extensions to novel conceptual mod- els. What is still missing, however, are models that focus on high-level security requirements, without forcing the modeler to immediately get down to security mechanisms. The modeling process itself should make it clear why encryption, authentication or access control are necessary, and what are the tradeos, if they are selected. In this paper we show that the i*/Tropos framework lacks the ability to capture these essential features and needs to be augmented. To motivate our proposal, we build upon a substantial case study {the modeling of the Secure Electronic Transactions e-commerce suites by VISA and MasterCard {to identify missing modeling features. In a nutshell, the key missing concept is the separation of the notion of oering a service (of a handling data, performing a task or fullling a goal) and ownership of the very same service. This separation is what makes security essential. The ability of the methodology to model a clear dependency relation between those oering a service (the merchant processing a credit card number), those requesting the service (the bank debiting the payment), and those owning the very same data (the cardholder), make security solutions emerge as a natural consequence of the modeling process.
机译:计算机安全是当今的热门话题之一,对安全功能概念模型的需求提出了许多建议,从UML扩展到新颖的概念模型。但是,仍然缺少专注于高级别安全性要求的模型,而没有强迫建模者立即采用安全性机制。建模过程本身应明确说明为什么需要加密,身份验证或访问控制,以及如果选择了什么,则是什么。在本文中,我们表明i * / Tropos框架缺乏捕获这些基本功能的能力,需要加以增强。为了激发我们的建议,我们以大量的案例研究为基础{由VISA和万事达卡对安全电子交易电子商务套件进行建模{以识别缺少的建模功能。简而言之,缺少的关键概念是将提供服务(处理数据,执行任务或完成目标)的概念与相同服务的所有权分开。这种分离使安全至关重要。该方法能够对提供服务的人(处理信用卡号的商人),请求服务的人(银行从付款中扣除)和拥有完全相同数据的人(持卡人)之间建立清晰的依赖关系的能力,使安全解决方案成为建模过程的自然结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号