A Formal Approach to Data Validation Constraints in MDE
Alessandro Marco Rossini, Khalid Azim Mughal, Uwe Wolter, Adrian Rutle, Yngve Lamo · 2011
Software security encompasses the measures taken to ensure confidentiality, integrity and availability in software systems. In present-day software development, security is often an afterthought rather than part of the software development life-cycle. In order to reveal potential security flaws before a software system is actually implemented, security aspects should be taken into account starting from the early phases of the development. With model-driven engineering (MDE) gaining momentum in both academia and industry, an interesting challenge is the specification of security constraints within so ftware models. In this paper we focus on data validation ‐ the process of ensuring that a system operates on correct and meaningful data ‐ in the context of MDE. Our contribution is a formal approach to the specification of data validation constraints which involve multiple structural properties. In addition, constraints specified at model level are mapped to Java annotations which are then transformed to executable tests by an existing data validation framework.