First step of security model for separation of concerns

Hamid Mcheick, Eric Dallaire, Hafedh Mili · 2009

The separation of concerns (SOC), as a conceptual tool, enables us to manage the complexity of the software systems that we develop. When the idea is taken further to software packaging, greater reuse and maintainability are achieved. One of the methods of SOC is view-oriented programming (VOP) in which an object can change its behaviors and play different roles (views) in their lifecycle. In VOP, an object's response to a message depends on the views currently attached to its core instance. This view-programming suffers from security issues to protect the privileges of each client who needs to access different views of the same object. In a previous article, we introduced a view security model based on changing the signature of each method to authenticate a client privileges to access object views. In this paper, we present the main parts of our views security model without changing each method signature. Java security model is applied to views to support transparent authentication. These issues are discussed through an example.

Read the paper · More papers on PaperTik