Engineering Trust Management into Software Models

  • Authors:
  • Mark Reith;Jianwei Niu;William H. Winsborough

  • Affiliations:
  • University of Texas at San Antonio, USA;University of Texas at San Antonio, USA;University of Texas at San Antonio, USA

  • Venue:
  • MISE '07 Proceedings of the International Workshop on Modeling in Software Engineering
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security in software is often considered a nonfunctional requirement because it is often interpreted as an emergent feature of the system. Too often it is introduced as a last-minute requirement over an otherwise completed product rather than properly integrated during the early stages of software design and development. One significant aspect of security involves access control. This paper proposes a multi-layer model detailing the integration of trust management access control with an application's model behavior. Our previous work focused on modeling the dynamic changes of a trust management policy for the purpose of verifying security properties using model checking. We are working toward integrating both the trust management policy and the mechanisms that enforce that policy for the purpose of verifying security properties. We focus on the Rolebased Trust Management (RT) language and suggest concerns specific to it.