Integration of Access Control Policy Design into Software Development
Ji Cheng · 2009
Security is an important part especially in complex software systems, but now it is not considered as an essential part in software development. There would be many difficulties and mismatches if security mechanisms are added to existing systems afterwards, so it is proposed to integrate the design of access control policy into software development. In this paper, UML is used to model access control policy, and then a compiler is designed as a plug-in component of UML tools to export the model result to XACML for complex distributed system. The mechanism supports the automatic generation of a XACML specification based on an extended RBAC.