Helping to Meet the Security Needs of Enterprises: Using FDAF to Build RBAC into Software Architectures

نویسندگان

  • Lirong Dai
  • Kendra Cooper
چکیده

The vision, strategies, and goals of enterprises involve numerous security issues; these stem from legal and business concerns. For example, a financial organization, such as a bank, needs to ensure that employee and customer data are kept private and account balances for customers are not corrupted. Some of these needs may be realized in a collection of software applications such as employee payroll, employee performance review, and account reconciliation systems. The problem of effectively designing secure software systems to meet an organization’s needs is a critical part of their success. This paper focuses on the problem of how to build security into a software architecture using the Formal Design Analysis Framework (FDAF). FDAF is an aspect-oriented approach that supports the design and analysis of non-functional properties for distributed, real-time systems. Particularly, an empirical study is presented to illustrate building Role-Based Access Control (RBAC), a design aspect in FDAF aspect repository, into the architecture for an online banking system. The RBAC aspect is adapted from the well-established RBAC security pattern. The study has also demonstrated how FDAF can help meet a system’s enterprise level security requirements.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Extending RBAC for Large Enterprises and Its Quantitative Risk Evaluation

Systems and security products based on the RBAC model have been widely introduced to enterprises. Especially, the demands on enforcement of enterprise-level security policies and total identity management are rapidly growing. The RBAC model needs to be extended to deal with various circumstances of large enterprises, such as geographical distribution and heterogeneous environments including phy...

متن کامل

Role Explosion: Acknowledging the Problem

In large enterprises subject to constant employee turnover and challenging security policies, the administration of Role-based Access Control (RBAC) is a daunting task that is often highly centralized in a small team of security administrators. The aim of this work is to determine why existing models for Administrative Role-based Access Control (ARBAC) have failed to achieve success and thus mo...

متن کامل

New Economic Instruments of State Regulation of Private Savings, Social Security and Pension Support

In the conditions of market infrastructure for the transformation of medical services, there is an objective need to build effective insurance protection of the population against risks associated with loss of health. Using a systematic approach, the problem of combining compulsory and voluntary health insurance is investigated, a theoretical conceptualization of the concept of “financial mecha...

متن کامل

Design and Implementation of Access Control as a Service for IaaS Cloud

Organizations and enterprises have been outsourcing their computation, storage, and workflows to Infrastructure-as-a-Service (IaaS) based cloud platforms. The heterogeneity and high diversity of IaaS cloud environment demand a comprehensive and finegrained access control mechanism, in order to meet dynamic, extensible, and highly configurable security requirements of these cloud consumers. Howe...

متن کامل

Enforcing RBAC Policies over Data Stored on Untrusted Server (Extended Version)

One of the security issues in data outsourcing is the enforcement of the data owner’s access control policies. This includes some challenges. The first challenge is preserving confidentiality of data and policies. One of the existing solutions is encrypting data before outsourcing which brings new challenges; namely, the number of keys required to access authorized resources, efficient policy u...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006