A Model Transformation Methodology for Security Integration and Code Generation from Sequence Diagram of System's Internal Behavior

Abdellatif Lasbahani, Mostafa Chhiba, Abdelmoumen Tabyaoui · International Review on Modelling and Simulations (IREMOS) · 2018

Recently, there have been many researches suggesting the inclusion of the security engineering in an early stage of system’s modeling and development of Model Driven Engineering (MDE). This concept consists in deploying Unified Modeling Language (UML) standard as a principal meta-model for different system’s abstractions. Although, most of these works have been addressing the security injection without taking into the account security infrastructure generation, generating the code corresponding to the functional and non-functional aspect at the same time. In this current work, authors have concentrated their efforts on non-functional aspects such as the business logic layer, data flow monitoring, and delivering high-quality services by developing a generic methodology for the security integration and the code generation that consider the security needs during the whole cycle of system development. Practically, a new UML profile for security integration and code generation for Java platforms has been proposed to improve the elements of the source model of Platform Independent Model (PIM) with the security integration rules for the verification and the validation of security policies, and to establish the mapping between annotated elements and the corresponding stereotypes, during the transition from CIM to PIM. The semantic definition of security was made literally by applying Larman’s new operation contracts semantics and security patterns, and concretely by applying the security formalism that was given through the new security metamodel. Finally, the objective is to improve the software applications productivity, interoperability, and generalize security integration on the entire software development life cycle rather than on the implementation phase.

Read the paper · More papers on PaperTik