Model based development of access policies

  • Authors:
  • Ruth Breu;Gerhard Popp;Muhammad Alam

  • Affiliations:
  • Universität Innsbruck Institut für Informatik, Research Group “Quality Engineering”, 6020, Innsbruck, Austria;Technische Universität München Institut für Informatik, Software and Systems Engineering, 85748, Garching b. Munich, Germany;Universität Innsbruck Institut für Informatik, Research Group “Quality Engineering”, 6020, Innsbruck, Austria

  • Venue:
  • International Journal on Software Tools for Technology Transfer (STTT)
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we present a novel approach for the specification of user rights in the context of an object oriented use case driven development process. Basically, we extend the specification of methods by a permission section describing the right of some actor to call the method of an object. Our approach is both role based and context based while allowing for permissions to be specified at a fine-grained data-dependent level. We use first-order logic with a built-in notion of objects and classes (provided with an algebraic semantics) as our syntactic and semantic framework. In the second part of the paper, we demonstrate the application of this approach in a model-based context to generate permissions in distributed peer-to-peer networks.