New Approach Targeting Security Patterns Development and Deployment

In this paper, we address the problems related to the applicability and usability of security patterns. In this context, we propose a new approach based on aspect-oriented programming (AOP) for security patterns development, specification and deployment. Our approach allows the security experts to d...

Full description

Saved in:
Bibliographic Details
Main Author: Mourad, Azzam (author)
Other Authors: Otrok, Hadi (author), Baajour, Lama (author)
Format: article
Published: 2011
Online Access:http://hdl.handle.net/10725/2682
http://dx.doi.org/10.1080/19393555.2011.607220
http://www.tandfonline.com/doi/abs/10.1080/19393555.2011.607220
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:In this paper, we address the problems related to the applicability and usability of security patterns. In this context, we propose a new approach based on aspect-oriented programming (AOP) for security patterns development, specification and deployment. Our approach allows the security experts to deliver their security patterns that describe the steps and actions required for security solutions, including detailed information on how and where to integrate each one. It also provides the pattern users with the capabilities to deploy well-defined security solutions. The pattern users are required to have knowledge in AOP with minimal expertise in the corresponding security solution domain. Moreover, we design and implement the RBAC (Role Based Access Control) model for a Library Circulation system called RBAC-LB. The elaborated RBAC-LB model illustrates all the procedures and mechanisms of the approach phases and provides authentication/access control features for the library system.