Extended description techniques for security engineering

  • Authors:
  • Guido Wimmel;Alexander Wisspeintner

  • Affiliations:
  • Technische Univ. München, München, Germany;Technische Univ. München, München, Germany

  • Venue:
  • Sec '01 Proceedings of the 16th international conference on Information security: Trusted information: the new decade challenge
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

There is a strong demand for techniques to aid development and modelling of security critical systems. Based on general security evaluation criteria, we show how to extend the system structure diagrams of the CASE tool AutoFocus (which are related to UML-RT collaboration diagrams) to allow modelling of security critical systems, in particular concerning components and channels. Both high-level and low-level models of systems are supported, and the notion of security patterns is introduced to provide generic solutions for security requirements. We explain our approach on the example of an electronic purse card system.