SecTOOL: supporting requirements engineering for access control

  • Authors:
  • Steffen Kolarczyk;Manuel Koch;Klaus-Peter Löhr;Karl Pauls

  • Affiliations:
  • Institut für Informatik, Freie Universität Berlin, Berlin, Germany;Institut für Informatik, Freie Universität Berlin, Berlin, Germany;Institut für Informatik, Freie Universität Berlin, Berlin, Germany;Institut für Informatik, Freie Universität Berlin, Berlin, Germany

  • Venue:
  • ETRICS'06 Proceedings of the 2006 international conference on Emerging Trends in Information and Communication Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

SecTOOL is a case tool for security engineering. It comes as an extension to traditional UML tools, taking into account access control requirements. In particular, it supports the developer in eliciting access control information from UML diagrams for the early phases, starting with requirements analysis and use case diagrams. Access control policies coded in VPL or XACML are generated from the diagrams; vice versa, textually coded policies can be visualized in UML diagrams. Design and usage of the tool are described, emphasizing its platform independence through XACML.