scieee Open visual document viewer

Injecting Quality Attributes into Software Architectures with the Common Variability Language

Horcas Aguilera, José Miguel; Pinto, Mónica; Fuentes, Lidia

Abstract

Quality attributes that add new behavior to the functional software architecture are known as functional quality attributes (FQAs). These FQAs are applied to pieces of software from small components to entire systems, usually crosscutting some of them. Due to this crosscutting nature, modeling them separately from the base application has many advantages (e.g. reusability, less coupled architectures). However, different applications may require differ-ent configurations of an FQA (e.g. different levels of secu-rity), so we need a language that: (i) easily expresses the variability of the FQAs at the architectural level; and that (ii) also facilitates the automatic generation of architectural configurations with custom-made FQAs. In this sense, the Common Variability Language (CVL) is extremely suited for use at the architectural level, not requiring the use of a particular architectural language to model base functional requirements. In this paper we propose a method based on CVL to: (i) model separately and generate FQAs cus-tomized to the application requirements; (ii) automatically inject customized FQA components into the architecture of the applications. We quantitatively evaluate our approach and discuss its benefits with a case study.

Full text

Injec ing Quali y A ibu es in o So wa e A chi ec u es wi h he Common Va iabili y Language Jose-Miguel Ho cas Uni e sidad de Málaga, Andalucía Tech, Spain ho [email protected] Mónica Pin o Uni e sidad de Málaga, Andalucía Tech, Spain pin [email protected] Lidia Fuen es Uni e sidad de Málaga, Andalucía Tech, Spain l @lcc.uma.es ABSTRACT Quali y a ibu es ha add new beha io o he unc ional so wa e a chi ec u e a e known as unc ional quali y a - ibu es (FQAs). These FQAs a e applied o pieces o so - wa e om small componen s o en i e sys ems, usually c oss- cu ing some o hem. Due o his c osscu ing na u e, modeling hem sepa a ely om he base applica ion has many ad an ages (e.g. eusabili y, less coupled a chi ec- u es). Howe e , diffe en applica ions may equi e diffe -en configu a ions o an FQA (e.g. diffe en le els o secu- i y), so we need a language ha : (i) easily exp esses he a iabili y o he FQAs a he a chi ec u al le el; and ha (ii) also acili a es he au oma ic gene a ion o a chi ec u al configu a ions wi h cus om-made FQAs. In his sense, he Common Va iabili y Language (CVL) is ex emely sui ed o use a he a chi ec u al le el, no equi ing he use o a pa icula a chi ec u al language o model base unc ional equi emen s. In his pape we p opose a me hod based on CVL o: (i) model sepa a ely and gene a e FQAs cus- omized o he applica ion equi emen s; (ii) au oma ically injec cus omized FQA componen s in o he a chi ec u e o he applica ions. We quan i a i ely e alua e ou app oach and discuss i s benefi s wi h a case s udy. Keywo ds CVL, quali y a ibu es, SPL, a iabili y, wea ing 1. INTRODUCTION The quali y o a so wa e sys em is measu ed by he ex- en o which i possesses a desi ed combina ion o quali y a ibu es (QAs) [2] such as usabili y, eliabili y, secu i y and scalabili y. Whe he o no a sys em will be able o exhibi i s desi ed (o equi ed) QAs is subs an ially de e mined by i s so wa e a chi ec u e, h ough he use o diffe en a chi- ec u al ac ics [3]. Fo some QAs, he a chi ec u al ac ic o be ollowed consis s in he injec ion (i.e. in oduc ion) o specialized elemen s in o he a chi ec u e (e.g. an au ho- iza ion mechanism o sa is y he secu i y QA) [3]. These QAs a e no mally known as unc ional quali y a ibu es (FQAs) [12], and a e diffe en om o he QAs such as cos o efficiency ha can be mapped o a chi ec u al o imple- men a ion decisions, bu no di ec ly o unc ional compo- nen s. Examples o FQAs a e e o handling, secu i y, con- ex awa eness, usabili y, pe sis ence, eco e y, e c. Ou main idea is o gi e p io i y o he FQAs ha a e equi ed by an applica ion om he ea ly s ages o he so - wa e de elopmen , based on h ee main con ibu ions: (1) he specialized elemen s equi ed o sa is ying he FQAs a e modeled sepa a ely om he base so wa e a chi ec u e; (2) hese elemen s a e hen semi-au oma ically injec ed in o he applica ion a chi ec u e; and (3) he app oach is imple- men ed using he Common Va iabili y Language (CVL) [10]. The mo i a ion o modeling FQAs sepa a ely om he base a chi ec u e is ha FQAs a e no mally equi ed by se - e al applica ions — i.e. hey a e ecu en , and mos o hem c osscu he sys em a chi ec u e. So, modeling hem sepa- a ely om he base applica ion has many ad an ages (e.g. eusabili y, less coupled a chi ec u es, e c.). Fo ins ance, an enc yp ion algo i hm used o enc yp he in o ma ion does no depend on he applica ion ha needs i . Also, diffe en applica ions may equi e diffe en le els o an FQA (e.g. se- cu i y). Fo example, a specific applica ion may equi e ac- cess con ol and anonymi y while ano he may equi e only enc yp ion, o may equi e a diffe en kind o enc yp ion al- go i hm. In o he wo ds, he e is much a iabili y in FQAs, and he So wa e A chi ec (SA) should be able o selec he se o specialized a chi ec u al elemen s ha need o be injec ed o ulfill he applica ion equi emen s ega ding a pa icula FQA, which is no a i ial ask. Rega ding he second pa o ou app oach, once we ha e gene a ed cus om models o he FQAs o a gi en applica- ion, hese models need o be injec ed in o he base model o he applica ion. Being inspi ed by Aspec -O ien ed Mod- eling (AOM)1, in ou app oach, fi s we iden i y and selec he poin s in he base model whe e he cus om FQA mod- els ha e o be injec ed, and hen au oma ically gene a e he applica ion a chi ec u e wo en wi h he cus omized FQAs. Finally, ou hi d con ibu ion is he echnical de ails o ou app oach. In o de o define a amily o FQAs, a lan- guage o model he a iabili y o FQAs is needed. Al hough mos o he a iabili y app oaches use Fea u e Models (FMs), hei main sho coming is ha an addi ional p ocess is e- 1h p://www.aspec -modeling.o g/ qui ed o gene a e an a chi ec u al configu a ion ha mee s an FM configu a ion. CVL is mo e sui able o use a he a chi ec u al le el, since i defines links be ween he a iabil- i y specifica ion and he p oduc line a chi ec u e (PLA). The ad an ages o using CVL a e: (i) i is an MOF-based a iabili y language and his means ha any MOF-based a chi ec u al language can be used wi h he a iabili y in- o ma ion o CVL; (ii) he links be ween he a iabili y and base a chi ec u al models make i possible o au oma ically gene a e so wa e a chi ec u e configu a ions, ensu ing ha hey ulfill he a iabili y specifica ion, (iii) he seman ic o he CVL a ia ion poin s can be ex ended, and (i ) CVL in- cludes he mos impo an cha ac e is ics o simila a iabil- i y models (e.g. FM) such as ca dinali y o a ia ion poin s, c oss- ee cons ain s, e c. Due o all hese ad an ages he e is a g ea in e es in he SPL communi y in adop ing CVL in hei p oposals [5, 6]. Bu , since bo h he CVL language and i s ool suppo a e no el, he effo o using CVL is cu en ly conside able. Summa izing, in his pape we p esen an SPL app oach based on he use o CVL o au oma ically gene a e, om a amily o eusable FQAs, so wa e a chi ec u e configu a- ions ha include cus om made FQAs. As discussed u he on, in Sec ion 3, his app oach is an ex ension o ou p e- ious wo k [11] and defines a mo e gene ic, in eg a ed and ex ensible app oach. One impo an con ibu ion is ha he cus om made FQAs a e au oma ically wo en wi h he base applica ion by ex ending he seman ic o he CVL a ia ion poin s. We quan i a i ely e alua e ou app oach by using app op ia e me ics o assess he benefi s o ou app oach, and illus a e i wi h an In elligen T anspo a ion Sys em case s udy. Also, we discuss he benefi s o using CVL in achie ing he goals posed in his pape . Besides his in oduc ion, Sec ion 2 p esen s he CVL, and desc ibes he case s udy used h oughou he pape . Sec ion 3 o e iews ou app oach and highligh s i s main no el ies in compa ison wi h ou p e ious wo k [11]. In Sec- ion 4 we explain in de ail how we model FQAs by using CVL. The cus omiza ion and injec ion o he FQAs in o he base applica ion o ou case s udy is explained in Sec ions 5 and 6, espec i ely. In Sec ion 7 we e alua e ou p oposal. Sec ion 8 discusses he ela ed wo k. Finally, Sec ion 9 con- cludes he pape and p esen s u he wo k. 2. BACKGROUND INFORMATION In his sec ion we b iefly summa ize CVL.2Then, he case s udy ollowed h oughou he pape is desc ibed. 2.1 CVL The CVL is a domain-independen language o speci ying and esol ing a iabili y o e MOF-complian models. CVL p o ides an execu able engine o au oma ically p o- duce a esol ed model om h ee main models: (1) he base model o e which he a iabili y is specified and esol ed. (2) The a iabili y model ha specificies he a iabili y in an abs ac le el wi h a iabili y specifica ions (VSpecs)and in a conc e e le el h ough a ia ion poin s. VSpecs a e ee s uc u es ep esen ing choices (“ ea u es” in mos SPL e - minologies) and can include logical cons ain s defined in a subse o he Objec Cons ain Language (OCL). Va ia ion poin s define specific modifica ions o be applied o he base 2Comple e desc ip ion in h p://www.omgwiki.o g/ a iabili y/ model du ing ma e ializa ion — i.e. he p ocess o ans- o ming a base model in o a configu ed p oduc model. (3) A esolu ion model ha p o ides esolu ions o he VSpecs in o de o ma e ialize a base model wi h a a iabili y model. The main cha ac e is ics o CVL ha we will use a e: Configu able uni (CU). Se o a ia ion poin s ha hides he in e nal o a base model, exposing a VIn e ace. Va iabili y in e ace (VIn e ace). G oup o VSpecs ha ha e o be esol ed o ma e ialize a CU. Composi e VSpec (CVSpec). VSpec ha is esol ed by esol ing o he VSpecs ha a e a iabili y in e aces. Opaque Va ia ion Poin (OVP). I allows cus omizing he seman ic o he exis ing CVL a ia ion poin s h ough a model ans o ma ion language. 2.2 Case S udy We mo i a e ou p oposal p esen ing a case s udy based on In elligen T anspo a ion Sys ems (ITSs) [1]. In his con ex , he e is a se o se ices (e.g. oad sa e y, wea he condi ions,. . . ) ha all equi e communica ion be ween e- hicles (V2V) and ia oadside access poin s (V2I). An ITS applica ion equi es specific secu i y se ices: p i acy, o p o ec he pe sonal in o ma ion o d i e s such as he ou e ollowed; in eg i y, o ensu e he da a au hen- ici y exchanged o e he ne wo k; and confiden iali y and au hen ica ion, o allow he d i e s o use ce ain se ices o V2I (e.g. paymen a elec onic oll). Con ex awa eness and usabili y FQAsa ealso equi edino de oob aincon- ex in o ma ion o he use (e.g. license de ec o , wea iness) o o he ca (e.g. GPS, p oximi y senso s) and o p o ide con ex ual help acco ding o he use s needs, espec i ely. 3. OUR PROPOSAL This sec ion p esen s a gene al o e iew o ou app oach (Figu e 1). We dis inguish h ee main s ages wi h wo diffe - en ac o s: (1) FQAs modeling, pe o med by a domain ex- pe in quali y a ibu es; (2) FQAs cus omiza ion o he e- qui emen s o a pa icula applica ion, and (3) FQAs wea - ing. S eps (2) and (3) a e pe o med by he SA. S age 1: FQAs modeling. In his s age, an expe in he domain o he QAs mod- els he a iabili y o FQAs ollowing he CVL app oach. To do his, he/she fi s builds he so wa e a chi ec u e o he FQAs by using any MOF-complian language (FQAs Base Model in Figu e 1), and hen defines a a iabili y model o he FQAs in CVL (FQAs Va iabili y Model). This sup- poses a no el y in compa ison wi h ou p e ious wo k [11] in which he FQAs had o be obliga o ily modeled wi h aspec - o ien ed so wa e a chi ec u es, making use o a p opie a y ADL and o p opie a y ools. Mos o he FQAs a e composed by many conce ns. The secu i y FQA, o example, is composed by access con ol, au hen ica ion, p i acy, in eg i y, and enc yp ion, among o he conce ns. Howe e , no all o he conce ns o an FQA a e equi ed by all he sys ems. Fo example, an applica ion may equi e only au hen ica ion and access con ol. Also, he domain expe needs o conside ha some o he con- ce ns o an FQA ha e dependencies be ween hem, such as he confiden iali y conce n ha depends on he enc yp ion conce n o ensu e ha all he in o ma ion is enc yp ed and canno be ob ained by hi d pe sons. We call hese depen- dency ela ionships be ween he conce ns o he same FQA, in aFQA-dependencies. Fu he mo e, FQAs affec each o he , so dependency ela ionships be ween diffe en FQAs mus also be conside ed. Fo ins ance, he con ex ual help conce n o he usabili y FQA depends on he au hen ica ion conce n o he secu i y FQA in o de o p o ide cus omized help based on he p e ious expe ience o he use . We call hese dependency ela ionships be ween conce ns o diffe en FQAs, in e FQA-dependencies. This supposes a diffe ence be ween ou app oach and o he p oposals ha add ess FQAs’ a iabili y (e.g. QADA [13], RiPLE-DE [4]), basically because hey model hese FQAs as pa o he domain analysis o an SPL, and no sepa a ely as we p opose. An impo an hing ha is wo h highligh ing is ha his s age is pe o med only once. This means ha he FQAs base model and he FQAs a iabili y model will be com- ple ely eused by any applica ion ha wan s o inco po a e hese FQAs in o i s so wa e a chi ec u e, jus by ollowing s ages 2 and 3 o ou app oach. S age 2: FQAs cus omiza ion. In he second s age o ou app oach, he SA c ea es a configu a ion o he FQAs (FQAs Resolu ion Model) acco d- ing o he equi emen s o a pa icula applica ion. This means ha hose a iable conce ns ha a e no equi ed by he base applica ion will no be inco po a ed in o he final applica ion. This s age is au oma ed by using he execu ion engine o CVL (CVL Execu ion) ha esol es he a iabili y o he FQAs a ia ion poin s. This is ano he no el y o his app oach. P e iously, in [11], an addi ional language had o be used o link he FQAs a iabili y model wi h he FQAs base model. Mo eo e , he cus omiza ion o he FQAs de- pended on he defini ion and ins an ia ion o aspec -o ien ed a chi ec u al empla es, which we e defined using ou p op i- e a y ADL. The CVL engine akes as inpu s he FQAs Reso- lu ion Model, heFQAs Va iabili y Model and he FQAs Base Model, and au oma ically de i es (ma e ializes) he esol ed model o he FQAs (FQAs Resol ed Model). This model only con ains he so wa e elemen s o he FQAs ha a e needed acco ding o he equi emen s o he applica ion. S age 3: FQAs wea ing. Once he FQA esol ed model has been gene a ed in he p e ious s age, he nex s ep consis s o “wea ing”, o com- posing, i wi h he so wa e a chi ec u e o he base appli- ca ion (Applica ion Base Model in Figu e 1). The ou pu o his wea ing p ocess is an applica ion a chi ec u e ha also inco po a es he FQAs (Applica ion Resol ed Model (appli- ca ion a chi ec u e + FQAs)). This wea ing is no a s aigh - o wa d ask since each FQA will ha e o be wo en a di - e en poin s o he base applica ions (join poin s) and, u - he mo e, each FQA’s conce ns will be wo en acco ding o a diffe en wea ing pa e n, depending on he seman ic o he conce n. Mo eo e , his should be done au oma ically, wi hou manually modi ying he applica ion a chi ec u e. Thus, he challenge he e is o define a p ocess ha sys- ema ically in eg a es high-le el quali y solu ions in o he base a chi ec u e o a gi en applica ion, bu wi hou ha - ing o unde s and he inne wo kings o he quali y solu- ions. In o de o do ha , we need o adap he CVL ap- p oach (see Sec ion 6). Fi s ly, ou based model is o med by wo models, he FQAs Resol ed Model and he Applica- ion A chi ec u al Model. Secondly, du ing he CVL Execu- Figu e 1: Ou app oach o modeling FQAs. ion he con ol mus be delega ed o a Model-2-Model en- gine (M2M Engine) such as QVT, in cha ge o pe o ming he wea ingo hese womodels.Thewea ingispe o medac- co ding o he wea ing in o ma ion p o ided by he Appli- ca ion Wea ing Model. This model uses he OVPs o CVL, which a e he mechanism p o ided by CVL o ex end he seman ic o he CVL a ia ion poin s. Using he OVPs he wea ing ules ha indica e whe e he FQAs mus be in- co po a ed in o he co e so wa e a chi ec u e a e specified as use -defined M2M ans o ma ions (Wea ing Rules (M2M ans o ma ions)). The wea ing p ocess in oduced he e, and de ailed in Sec ion 6, is a new con ibu ion o his pa- pe and was no pa o he p oposal p esen ed in [11]. The es o he pape desc ibes each s age in mo e de ail, using he case s udy desc ibed in he p e ious sec ion. 4. MODELING FQAS WITH CVL This sec ion desc ibes he fi s s age o ou app oach, in which he FQAs (secu i y, con ex awa eness, and usabili y), hei commonali ies and a iabili ies, and he dependencies be ween hem a e modeled. 4.1 FQAs base model In ou app oach he FQAs Base Model specifies he so wa e a chi ec u e o he FQAs. Fo ins ance, he UML so wa e a chi ec u e modeling he unc ionali y o he diffe en con- ce ns o he secu i y FQA is shown a he bo om o Fig- u e 2. This a chi ec u al model should include he comple e unc ionali y o he secu i y FQA. In o de o simpli y he model, we only include he e he In eg i y,Con iden iali y, Enc yp ion,Au hen ica ion,andHash componen s. These a e composi e componen s ha include o he necessa y compo- nen s o implemen he unc ionali y o each conce n. Fo ins ance, Enc yp ion includes componen s o enc yp and de- c yp in o ma ion using diffe en enc yp ion algo i hms. In o de o achie e a be e modula iza ion we model each FQA independen ly o each o he and hen we model he de- pendencies and in e ac ions be ween hem. Thus, he bo - om o Figu e 3 shows he high-le el a chi ec u al model o all he FQAs oge he . Al hough no included due o Secu i y_In Secu i y_CU Con iden iali y Au hen ica ion Use PassAu h Ca dAu h Au hLogging BioAu h Symme ic Asymme ic 1..1 1..1 1..* Enc yp ion P i acy Au hen ica ion In eg i y SHA-2 MD5 Hash Enc yp ion Secu i y 1..1 Hash :Objec Exis ence DSA RSA ECDSA AES DES 1..* 1..* SHA-1 ... Limi edSession Secu i y_C KeyS o age PseudonymousCe i ica e Op ional Manda o y Choice OCL Cons ain min..max Mul iplici y Binding Base model e e ence Composi e VSpec Va iabili y In e ace Con igu able Uni :LinkExis ence :Objec Exis ence :Objec Exis ence :LinkExis ence :Objec Exis ence :Objec Exis ence VSpec ee Va ia ion poin s Base model Figu e 2: Modeling secu i y FQA in CVL. he lack o space, he so wa e a chi ec u es o he con ex awa eness and he usabili y FQAs a e modeled in a simila way as o he secu i y FQA. 4.2 FQAs a iabili y model Once he FQAs base model has been specified, he nex s ep is o model he FQAs Va iabili y Model.ThisCVL a i- abili y model includes he VSpecs, he a ia ion poin s, he bindings be ween he a ia ion poin s and he VSpecs, and he e e ences om he a ia ion poin s o he base model. As an example, he a iabili y model o he secu i y FQA is shown in Figu e 2. We dis inguish h ee pa s: (1) he VSpec ee o he secu i y FQA ( op o Figu e 2), (2) he base model o he secu i y FQA (bo om o Figu e 2), and (3) he a ia ion poin s (middle o Figu e 2). The a ia- ion poin s a e g ouped in o he secu i y configu able uni (Secu i y_CU). Then, he Secu i y_CU is bound o a com- posi e VSpec (Secu i y_C ) which e e s o he a iabili y in e ace Secu i y_In — i.e. he VSpec ee. In he Secu i y_In VSpec we iden i y all he conce ns ha a e pa o he secu i y a ibu e, model hem by choices whose la e esolu ion equi es a yes/no decision, indica e which a e op ional and which a e manda o y, and wha he in aFQA-dependencies be ween hem a e. As s a ed, in his VSpec ee we only show a subse o he secu i y conce ns. These conce ns a e also composed by o he conce ns. Fo ins ance, he e a e diffe en kinds o au hen ica ion: use + passwo d (Use PassAu h), in elligen ca d (Ca dAu h), and biome ic (BioAu h). The kind o a iabili y ha we need o exp ess is ha “no all o he conce ns o an FQA a e equi ed by an ap- plica ion and hus, no all o he componen s o ha FQA base model need o be inco po a ed in o he applica ion a - chi ec u e”. In CVL his kind o a iabili y is exp essed by using he “exis ence” a ia ion poin ha indica es he exis- ence o a pa icula objec , link, o alue in he base model. Finally, in CVL, he a ia ion poin s need o be bound o elemen s o he VSpec ee and need o e e o elemen s o he FQA base model. This is how he ela ionship be ween he a iabili y model and he base model is specified in CVL. Mo eo e , hese links a e used by he CVL execu ion engine o au oma e he gene a ion o a p oduc configu a ion. Fo ins ance, he a ia ion poin bound o he Con iden iali y conce nin heSecu i y_In VSpec (:Objec Exis ence)in- dica es ha i confiden iali y is decided posi i ely (ma ked as “T ue” in he esolu ion model) in a configu a ion, he ela ed elemen s ( he Con iden iali y componen and he associa ed in e aces and po s wi h hei a achmen s) in he base model will exis in he final applica ion and i con- fiden iali y is decided nega i ely (ma ked as “False” in he esolu ion model) hose ela ed elemen s will be emo ed om he FQA esol ed model. In o de o main ain he consis ency and o achie e a good modula iza ion o he design, we speci y he a iabil- i y model a he same abs ac ion le el as we did o he FQA base model. This means ha he a iabili y o each FQA is specified independen ly om he a iabili y o he o he FQAs. This can be done in CVL by using composi e VSpecs and configu able uni s. Then, we ela e he diffe en a iabili y models defining a “comple e” a iabili y model including all he FQAs wi h hei ela ionships (Figu e 3). We apply he concep ual in eg i y p inciple3 o compose he diffe en FQAs configu able uni s. As Figu e 3 shows, he FQAs VSpec includes he h ee FQAs by including he h ee 3The o e all design pa e n o a sys em is eflec ed in any pa o he sys em. composi e VSpecs p e iously c ea ed (Secu i y_C ,Usabil- i y_C ,andCon ex Awa eness_C ). These VSpecs e e o he in e aces o he configu able uni o each FQA (Secu i y_CU, Usabili y_CU,andCon ex Awa eness_CU). Each configu able uni e e s o i s own composi e componen in he FQAs base model (bo om o Figu e 3). Each o hese componen s ha e inne a iabili y ha we ha e p e iously modeled o each FQA. 4.2.1 Dependency modeling Ou app oach models he dependencies by using he CVL cons ain s. CVL cons ain s exp ess ela ionships be ween elemen s o he VSpec ha canno be di ec ly defined by hie a chical ela ions. We define he in aFQA- and he in e FQA-dependencies a a diffe en le el o abs ac ion: in aFQA-dependencies a e defined in he con ex o each FQA configu able uni while in e FQA-dependencies a e de- fined in he con ex o he comple e FQAs a iabili y model. In aFQA-dependencies. In Figu e 2, each in aFQA- dependency is ep esen ed by a p eposi ional cons ain (ex- p essed in OCL) in a pa allelog am ha cap u es a condi ion in a choice. Fo ins ance, he dependency 'confiden iali y equi es enc yp ion'is modeled by a aching he cons ain Enc yp ion o he choice Con iden iali y.Thus, hechoice Enc yp ion has o be posi i ely decided whene e Con iden- iali y is posi i ely decided. Dependencies a e also p esen ed in he secu i y base model. Fo ins ance, al hough confiden iali y affec s da a in gen- e al and only equi es enc yp ion, p i acy also affec s peo- ple’s in o ma ion and equi es he au hen ica ion o he use . So, he e is a dependency be ween he p i acy conce n and he au hen ica ion conce n. In Figu e 2, he a ia ion poin (:LinkExis ence) bound o he P i acy choice e e s o a e- qui ed in e ace o he Con iden iali y componen in he UML secu i y base model. This link ep esen s he depen- dency ela ionship be ween he p i acy and he au hen ica- ion conce ns. The a ia ion poin indica es he exis ence o ha pa icula link. I P i acy is decided posi i ely in a es- olu ion model he link will exis in he esol ed model, and i P i acy is decided nega i ely, he link will be emo ed. In e FQA-dependencies. The FQAs_In VSpec o Fig- u e 3 includes he CVL cons ain s ha speci y he in e FQA- dependencies. Fo ins ance, he cons ain Au hLogging im- plies His o yLog ep esen s he dependency be ween he au- hen ica ion logging conce n o he secu i y FQA and he his o y log conce n o he usabili y FQA, and means ha i he Au hLogging choice is decided posi i ely, he His o- yLog choice has o be posi i ely decided oo. In e FQA- dependencies a e also p esen ed in he FQAs base model. I shows how he Secu i y componen ela es wi h he Con ex - Awa eness and Usabili y componen s due o he exis ing de- pendencies be ween hem. Fo ins ance, Au hen ica ion is equi ed by Usabili y in o de o p o ide con ex ual help. Also, Secu i y equi es Feedback om Usabili y and TimeAwa e om Con ex -Awa eness in o de o allow he au hen ica ion logs and he con ol o he session ime espec i ely. Finally, Con ex -Awa eness equi es Feedback o p o ide ale s when he in o ma ion con ex demands i . 5. CUSTOMIZATION OF THE FQAS In he second s age o ou app oach a alid configu a ion (cus omiza ion) o he FQAs a iabili y model is gene a ed, FQAs_In FQAs_CU Secu i y_CU Con ex Awa eness_CU Usabili y_CU FQAs 1..* Secu i y_C Con ex Awa eness_C Usabili y_C FQAs_C Au hLogging implies His o yLog Limi edSession implies TimeAwa e Wea iness implies Ale s Con ex ualHelp implies Au hen ica ion Figu e 3: FQAs a iabili y model. aken as inpu he equi emen s o he applica ion unde de elopmen , which in ou case is he ITS case s udy. As shown in Figu e 1, he cus omiza ion o he FQAs im- plies he defini ion o a FQAs Resolu ion Model.A esolu ion model is c ea ed by deciding which choices o he VSpec ee a e posi i ely decided and which ones a e nega i ely decided. The VSpec a he op o Figu e 44shows a alid configu a ion o he FQAs (a esolu ion model) ha sa isfies he equi emen s o ou ITS applica ion. Some o he choices shown in Figu e 4 ha e been selec ed because he applica- ion equi emen s explici ly iden ified hem as needed, such as p i acy, in eg i y, confiden iali y, au hen ica ion, loca ion awa e, use awa e and con ex ual help. O he conce ns, such as enc yp ion, hash, eedback, and ime awa e, had o be se- lec ed in o de o ob ain a alid configu a ion due o he ex- is ing dependencies be ween hose conce ns and hose ha we e o iginally equi ed. Fo ins ance, he e a e conce ns ha had o be selec ed due o he pa en -child ela ionship in he VSpec (e.g. he Con iden iali y and he P i acy choices). O he conce ns had o be selec ed because o he in aFQA-dependencies be ween conce ns o he same FQA (e.g. Con iden iali y and Enc yp ion). Finally, o he conce ns had o be selec ed due o he in e FQA-dependencies be ween conce ns o di - e en FQAs (e.g. Au hLogging o he Au hen ica ion conce n in he secu i y FQA and Log o he usabili y FQA). Thus, in ou case s udy, he e a e conce ns, as is he case o he enc yp ion o he hash conce ns, ha a e equi ed by o he conce ns bu had no explici ly specified as pa o he applica ion equi emen s. This occu s basically because hese dependencies a e no always ob ious o he applica ion equi emen s enginee o he SA. By ha ing a domain expe speci ying he in aFQA- and in e FQA-dependences as pa o he defini ion o he FQAs a iabili y in he fi s s age o ou app oach, in his second s age ou app oach helps he SAs o speci y so wa e a chi ec u es ha a e mo e accu a e ega ding he specifica ion and cus omiza ion o he FQAs o he necessi ies o he applica ions. Once he esolu ion model has been c ea ed, he CVL Exe- cu ion engine is execu ed o au oma ically gene a e he FQAs Resol ed Model, which is shown in Figu e 5. Only he nec- essa y unc ional componen s a e included in he esul ing FQAs so wa e a chi ec u e. 4Middle and bo om o Figu e 4 a e desc ibed in he nex sec ion. We show only one figu e o easons o space. Wea ing ules FQAs esol ed model (FQAsModel) Con iden iali y Ca dAu h Au hLogging 1..* Enc yp ion P i acy Au hen ica ion In eg i y HashEnc yp ion Secu i y Hash ECDSA SHA-2 Limi edSession KeyS o age Au hen ica ion Asymme ic TimeAwa e 1..* Loca ionAwa e Con ex Awa eness Use Awa e Wea iness TimeAwa e GPS P oximi ySenso LicenseDe ec o 1..* FQAs 1..* Au hLogging implies His o yLogs Limi edSession implies TimeAwa e Wea iness implies Ale s Con ex ualHelp implies Au hen ica ion PseudonymousCe i ica e OpaqueVa ia ionPoin 1 Applica ion a chi ec u al model (appModel) OpaqueVa ia ionPoin 2 OpaqueVa ia ionPoin 3 SpecialSubs i u ionAu h spec ype SpecialSubs i u ionEnc yp spec ype ... ... FQAs esolu ion model used as VSpec ee o he Applica ion Wea ing model sou ceObjec a ge Objec Feedback His o yLog Ale s 1..* Con ex ualHelp Usabili y Logs 1..* Seman icSpec1 Seman icSpec2 VSpec ee ( esolu ion model) Va ia ion poin s Base models Figu e 4: CVL model o he injec ion o he FQAs inside he applica ion a chi ec u e. 6. WEAVING THE CUSTOMIZED FQAS A his poin , an a chi ec u al model cus omized wi h he equi ed FQAs and conce ns has been gene a ed (high le el iew in he FQAsModel in Figu e 4 and low le el iew in Fig- u e 5). Now, in he hi d s age o ou app oach his FQAs esol ed model has o be inco po a ed in o he so wa e a - chi ec u e o he co e applica ion (appModel in Figu e 4). As p e iously s a ed, each conce n o he FQAs needs a pa icula ans o ma ion because i is wo en wi h he ap- plica ion in a diffe en way. The Applica ion Wea ing Model (Figu e 4) uses he OVPs o CVL o define a new seman ic o a a ia ion poin using model ans o ma ion ules. The s eps a e: (1) binding an OVP o each o he conce ns o he FQAs in he esolu ion model (e.g. enc yp ion, con ex- ual help); (2) speci ying a e e ence o he specific a chi ec- u al elemen s ha model ha conce n in he FQAs esol ed model, and (3) indica ing how he conce n will be wo en wi h he applica ion base model. OVPs a e also bound o an OVPType, whe e his ype explici ly defines he seman- ic o a special subs i u ion. A special subs i u ion implies he combina ion o a s anda d subs i u ion and use defined ans o ma ions. In ou case he special subs i u ion is done om he “sou ce objec ” o he “ a ge objec ” e e enced by he OVP as we show in Figu e 4. Based on his special subs i u ion he SA needs o e e o one o mo e join poin s ( a ge objec s) in he applica ion model whe e he beha io o he selec ed conce n (sou ce objec ) will be inco po a ed. We ha e iden ified a se o wea ing pa e ns (Table 1) ha ulfil ou needs o inco po a e he FQAs conce ns based on how he unc ionali y o he conce ns (ad ices) needs o be applied in o he diffe en poin s o he applica ion (join poin s). The special subs i u ion needed by each conce n is mapped o one wea ing pa e n p esen ed in Table 1.5Fo ins ance, he p i acy and he au hen ica ion conce ns ha e he same special subs i u ion ha indica es ha only one ad ice (e.g. au hen ica e()) o he selec ed conce n (e.g. au hen ica ion) is wo en in o he selec ed join poin (e.g. an in e ace o he base applica ion). Con inuing wi h ou example, o simpli y Figu e 4, we only show h ee OVPs bound o h ee conce ns: confiden- iali y, which is achie ed using enc yp ion, p i acy, and au- hen ica ion. Fo ins ance, he OpaqueVa ia ionPoin 1 is bound o he P i acy conce n in he VSpec ee and i is also bound o he OVPType SpecialSubs i u ionAu h6 (OVPType 1 in Table 1). This in u n specifies he seman- ics o he special subs i u ion wi h he necessa y ans o - ma ions (wea ing ules) o inco po a e he ela ed elemen (Con iden iali y ha con ains he P i acy unc ionali y) o he FQAs esol ed model (FQAsModel in Figu e 4) in o he applica ion base model (AppModel in Figu e 4). Algo i hm 1 shows he wea ing p ocess du ing he a i- abili y esolu ion pe o med by he CVL engine. I akes he se o OVPs defined (SOV P ) and o each OVP he seman- ic o he special subs i u ion associa ed (OVPType) is exe- cu ed by he M2M ans o ma ion engine (line 4). Sjoinpoin s is he se o join poin s e e enced by he OVP. When CVL is execu ed aking as inpu s he applica ion wea ing model, he applica ion base model (appModel) and he FQAs esol ed model, he ou pu is an au oma ically gene a ed model ep- esen ing he comple e applica ion so wa e a chi ec u e (Fig- u e 6), which includes he cus om FQAs. No e ha he configu a ion o he a chi ec u e ( he com- ponen s and hei ela ionships) is clea ly isible in he s a ic pa o he design. Addi ionally, s e eo yped dependencies 5Implemen a ion in ATL o he M2M ans o ma ions a e a ailable in h p://caosd.lcc.uma.es/spl/c l/CVL-models- ans o ma ions.zip 6In ou app oach p i acy is achie ed using au hen ica ion. «componen » Con ex -Awa eness «componen » Use Awa e «componen » Wea inessDe ec o «componen » LicenseDe ec o «componen » Use Awa e Manage TimeAwa e «componen » Loca ionAwa e «componen » Loca ion Manage «componen » P oximi y Senso «componen » GPS «componen » TimeAwa e «componen » Secu i y «componen » Au hen ica ion «componen » Pseudonymous Ce i ica e «componen » Session Manage «componen » Digi al Iden i y TimeAwa e Logs «componen » Enc yp ion «componen » Key Reposi o y «componen » Enc yp ion Manage «componen » ECDSA «componen » Hash «componen » HashManage «componen » SHA-2 «componen » Con iden iali y «componen » In eg i y Hash «componen » Usabili y «componen » Feedback «componen » Ale s «componen » Logs «componen » Con ex ual Help Au hen ica ion Con ex ual Help Loca ionAwa e Au hen ica ion Con iden iali y TimeAwa e Use Awa e Enc yp ion Feedback In eg i y Hash Figu e 5: FQAs esol ed model. Table 1: Special subs i u ions. OVPType Desc ip ion Example 1 Only one ad ice o a conce n is wo en in o a join poin . Au hen ica ion: he au hen ica e() ad ice is pe o med a ound he join poin . 2 The same ad ice is wo en mul iple imes in o a join poin . Time awa e:cu en Time() is applied wice (be o e and a e ) o measu e he ime session o he use . 3 The same ad ice is wo en in o diffe en join poin s. Loca ion awa e: he acqui ePosi ion() ad ice needs o be applied on he clien and on he se e side o es ablish loca ions. 4 Mul iple ad ices o he same conce n a e wo en in o a join poin . Feedback:log() ad ices a e in oked be o e and a e he join poin . 5 Mul iple ad ices o he same conce n a e wo en in o diffe en join poin s. Enc yp ion: enc yp he in o ma ion (enc yp (Objec ))be o e sending i and de- c yp i (dec yp (Objec ))a e ecei ing i . 6 Ad ices o diffe en conce ns a e wo en in o a join poin . Con ex ual help: fi s check whe he he use is au hen ica ed (isAu hen ica ed()) and hen show in o ma ion (showHelp()) based on he p e e ences o he use . 7 Ad ices o diffe en conce ns a e wo en in o diffe en join poin s. In eg i y:hash(Objec ) is applied be o e sending in o ma ion o he se e and checkIn eg i y(Objec ) is applied be o e use he in o ma ion in he se e . Algo i hm 1 Wea ing p ocess using CVL. Requi e: SOV P Ensu e: Resol edModel 1: o all p in SOV P do 2: c← p.sou ceObjec 3: Sjoinpoin s ← p. a ge Objec s 4: Resol edModel ←specialSubs i u ion(c,Sjoinpoin s, p. ype) 5: end o 6: e u n Resol edModel be ween componen s o he FQAs and componen s o he base applica ion make explici ha he sou ces o he ela- ionships c osscu s he a chi ec u al le el, and he a ge s a e he poin o he applica ion whe e hey ake place (i.e. he join poin s in he AOM e minology). Howe e , his is insufficien because he in e ac ions be ween he compo- nen s a e no ep esen ed. In o de o sol e his limi a- ion, in ou app oach he in e ac ions be ween he compo- nen s a e ep esen ed in a se o sequence diag ams ha a e also au oma ically gene a ed [14] by he ans o ma ion ules o he special subs i u ions. Fo ins ance, he beha io o he c osscu ing ela ionship o he au hen ica ion con- ce n is ep esen ed in he sequence diag am in Figu e 6 (b). This diag am shows how he V2V componen in okes he paymen Toll() me hod o he In aSe ice in e ace, and ha be o e he call is effec i e he au hen ica e() me hod o he Au hen ica ion componen is in oked. Simila ly, he sequence diag am o Figu e 6 (c) shows he beha io o he enc yp ion conce n when he V2V componen ansmi s in- o ma ion; ha is, be o e sending he message o he Commu- nica ion componen he enc yp () me hod o he Enc yp ion componen is in oked. 7. EVALUATION We e alua e ou wo k bo h quan i a i ely, by using me - ics o quan i y he benefi s p o ided by ou app oach, and quali a i ely, when he use o a me ic does no make sense. Table 2 desc ibes he me ics sui e ha ha e been used o e alua e ou app oach. Using hese me ics we ha e iden i- fied ha he e is: (1) a deg ee o dependency be ween FQAs (me ics 1–3). This means ha he e is a significan numbe o conce ns whose inclusion in a pa icula solu ion depends on he co ec iden ifica ion o hese dependencies, which a e no always s aigh o wa dly de i ed om he equi e- men s o he sys em. Consequen ly, hese dependencies may go unno iced by he SA e en i hey should be aken in o accoun o sa is y he equi emen s o a sys em; (2) a high deg ee o a iabili y (me ics 4–6), since modeling he FQAs as a “ amily” o p oduc s, and he au oma ic ma e ializa ion o he FQAs base model conside ably inc eases he num- be o “ alid” esolu ions o a FQA ha can be gene a ed; (3) a high deg ee o au oma ion, due o he high numbe o a chi ec u al elemen s ha a e au oma ically gene a ed in compa ison wi h he manual effo ha needs o be made in o de o include he FQAs inside he so wa e a chi ec u es o he applica ions. This deg ee o au oma ion implies a lowe de elopmen effo and gains in p oduc i i y; and (4) ahighdeg ee o sepa a ion o conce ns (me ics 7–8), which is imp o ed due o spli ing ou app oach in o h ee s ages. We p esen he esul s o modeling he h ee FQAs de- sc ibed in his pape : secu i y, con ex awa eness and us- abili y. Figu e 6: Comple e applica ion a chi ec u e (a); au hen ica ion (b) and enc yp ion (c) sequence diag ams. Table 2: Me ic Sui e Dependency Me ics 1. #in aFQA-dependencies: I measu es he numbe o dependencies ( ee-cons ain s and OCL cons ain s) be ween he conce ns o a FQA. 2. #in e FQA-dependencies: I measu es he numbe o dependencies (c oss ee-cons ain s and OCL cons ain s) be ween diffe en FQAs. 3. #dependen -elemen s: I measu es he minimum numbe o a chi ec u al elemen s (componen s, in e aces, ela- ionships,.. . ) ha need o be defined due o he exis ence o a dependency. Va iabili y Me ics 4. #choices: I measu es he o al numbe o choices in a VSpec. 5. # esolu ions: I measu es he o al numbe o alid esolu ions ha can be gene a ed om a VSpec. 6. Va iabili y le el: Exp essed as he a io #choices:# alid esolu ions. Sepa a ion o Conce ns Me ics 7. Lack o conce n-based cohesion (LCC): I measu es he numbe o conce ns angled in a pa icula componen . 8. Conce n diffusion o e a chi ec u al componen s (CDAC): I measu es he numbe o componen s in which a conce n is sca e ed. Deg ee o Dependency. The deg ee o dependency o he FQAs is shown in Ta- ble 3. By applying he dependency me ics (see Table 2), we coun he numbe o in aFQA- and in e FQA- dependen- cies, as well as he numbe o a chi ec u al elemen s ha a e needed in o de o sa is y hose dependencies. No e ha hese numbe s co espond only wi h he conce ns o he h ee FQAs p esen ed in his pape . A his poin , we would like o highligh ha each FQA dependency can imply he inco po a ion o a conside able numbe o a chi ec u al elemen s in o he so wa e a chi ec- u e. Fo ins ance, he secu i y FQA has only ou in aFQA- dependencies bu , in o de o sa is y hese ou dependen- cies, he SA needs o define a leas 33 a chi ec u al ele- men s. In e FQA-dependencies a e e en mo e difficul o sa is y because hey in ol e conce ns o he o he FQAs. Fo ins ance, o sa is y he in e FQA-dependency o he us- abili y FQA wi h he secu i y FQA, he SA needs o define a leas 13 a chi ec u al elemen s. The ele an issue he e is ha , using ou app oach, his complexi y is no managed di ec ly by he SA. Basically, because we make hose dependencies explici o make su e he/she is made awa e o hem and mus only selec he desi ed conce ns ha sa is y he dependencies. Then, he equi ed a chi ec u al elemen s a e au oma ically inco po- a ed in o he a chi ec u e. No e ha his is ce ain only by assuming ha he domain expe s co ec ly do hei job o modeling he FQAs and he dependencies be ween hem. Table 3: Deg ee o dependency Dependencies Secu i y Con ex awa eness Usabili y #in aFQA 4 3 1 #elemen s 33 12 3 #in e FQA 2 1 1 #elemen s 21 11 13 Table 4: Deg ee o a iabili y Secu i y Con ex awa eness Usabili y To al #choices 23 15 10 48 #componen s 21 19 7 47 # esolu ions 5354 575 79 313784 Deg ee o Va iabili y. Table 4 shows he numbe o choices ha we e specified in he VSpec o he secu i y, he con ex awa eness, and he usabili y FQAs, he numbe o componen s ha we e defined in he so wa e a chi ec u e o each FQA and he numbe o diffe en “ alid” esolu ions (configu a ions) ha can be gene a ed using ou app oach. The numbe o possible esolu ions will depend on he numbe o ini ial choices and on he numbe o dependen- cies be ween choices in he VSpec. In Table 4, we see ha , o secu i y, he domain expe will only once ha e o make, he effo o defining a VSpec wi h 23 choices and o speci- ying an a chi ec u al model wi h 21 componen s. Then he CVL engine au oma ically gene a es one o he 5354 alid secu i y configu a ions based on he selec ions in he VSpecs done by he SA. The co ec ness o he gene a ed so wa e a chi ec u es will depend on he co ec specifica ion o he a iabili y model. The a iabili y le el is lowe o con ex Table 5: Deg ee o au oma ion Case s udy Specified elemen s Deg ee o au oma ion manually au oma ically ITS 27 25 48.08% HW 42 38 47.50% TS 115 16 12.20% CS 43 34 44.20% awa eness (15 choices: 575 esolu ions) and usabili y (10 choices: 79 esolu ions) han o secu i y. These numbe s indica e ha some FQAs ha e a high de- g ee o a iabili y — i.e. he e a e many diffe en configu a- ions o secu i y ha can be c ea ed o sa is y he secu i y equi emen s o diffe en applica ions, and he manual spec- ifica ion o hese configu a ions by he SA (5354 in he case o secu i y) is a ha d and e o -p one ask. So, his me ic indica es ha he use o an SPL app oach makes sense. Deg ee o Au oma ion. Defining he a chi ec u al model o he FQAs and he a i- abili y model wi h he VSpecs and he a ia ion poin s is a difficul and specialized ask. Howe e , in ou app oach, his effo only needs o be made once and hen he FQA models can be eused in he de elopmen o many sys ems. The e o e, he main effo consis s o modeling he co e a - chi ec u e o he applica ion. Thus, in o de o speci y he deg ee o au oma ion o ou app oach, we compa e he num- be o a chi ec u al elemen s (i.e. componen s, p o ided and equi ed in e aces, and ela ionships) ha a e manually c e- a ed in he specifica ion o he co e so wa e a chi ec u e wi h he numbe o a chi ec u al elemen s ha a e au o- ma ically gene a ed, as defined in Equa ion 1. This is an adap a ion o he deg ee o au oma ion defined in [8], o be able o use his me ic a he a chi ec u al le el. Basically, a he a chi ec u al le el, he complexi y o defining a so - wa e a chi ec u e is measu ed by he complexi y o designing hei componen s, in e aces, and he ela ionships be ween hose componen s; and i does no depend on he complexi y o he pa icula implemen a ion o he componen s. Deg ee o Au oma ion = #elemen s FQAs #elemen s co e +#elemen s FQAs (1) We ha e applied he deg ee o au oma ion in ou ap- p oach when: (1) secu i y, con ex awa eness and usabili y a e added o he ITS case s udy, and (2) secu i y and us- abili y a e added o a heal h wa che (HW) indus ial case s udy, a oll (TS) case s udy and a c isis managemen (CS) case s udy (see Table 5). We no e ha , in he case s udy o his pape , he co e applica ion is composed by 27 a chi- ec u al elemen s, and when he FQAs a e inco po a ed, 25 new elemen s a e added o he a chi ec u e, ob aining a de- g ee o au oma ion o 48.08%. This alue is highe han in o he case s udies because he ITS equi es mo e QAs con- ce ns, and hose conce ns ha e many dependencies be ween hem. Thus, he esul s ob ained by applying his me ic indica es ha ou app oach can be use ul. Howe e , an em- pi ical s udy ha imply SAs de eloping p ojec s o diffe en complexi ies using ou app oach needs o be pe o med o confi m he benefi s sugges ed by his me ic. Deg ee o Sepa a ion o Conce ns. In ou app oach, he sepa a ed modeling o he FQAs om he co e applica ion a chi ec u e and he subsequen combi- na ion wi h he use o CVL and he c osscu s ela ionships all con ibu e o imp o e he sepa a ion o conce ns. On he one hand, we ha e modeled each FQA sepa a ely om each o he in o de o (1) iden i y he conce ns and hei depen- dencies, and (2) a oid he duplica ion o conce ns in diffe en FQAs. The esul is ha he conce ns o he FQAs a e well- encapsula ed only in hose componen s ha we e pa o he secu i y, he con ex awa eness, and he usabili y composi e componen s ( he CDAC me ic o all o hem is 1). The LCC me ic has also been applied o he same componen s, and he esul s show ha hey only con ain secu i y, con ex awa eness, o usabili y conce ns, espec i ely, and he in o - ma ion o he equi ed conce ns o he o he FQAs o sa is y hei dependencies. On he o he hand, his good deg ee o sepa a ion is kep a e he inco po a ion o he FQAs in o he applica ion a chi ec u e due o he use o he c osscu s ela ionships a he a chi ec u al le el. 7.1 Discussion The e alua ion esul s ob ained indica e ha he effo o sepa a ely defining FQAs o ming an SPL amily p esen s he ollowing ad an ages: (i) helps he SA o iden i y he dependencies, ake hem in o accoun and esol e hem; (ii) helps he SA o c ea e diffe en configu a ions o he FQAs; (iii) helps he SA o inco po a e he cus omized FQAs in o he a chi ec u e; (i ) he e is a be e deg ee o sepa a ion o conce ns due o he encapsula ion o he c osscu ing beha - io o he FQAs in sepa a e so wa e componen s. This acil- i a es he subsequen modifica ion o he applica ion and/o he FQAs. The ini ial esul s ob ained by some o he me - ics (deg ee o dependency and deg ee o a iabili y) suppo ou decision o use echniques and ools o SPLs o model- ing he FQAs. O he s (sepa a ion o conce ns) suppo ou decision o model hem sepa a ely om he base applica- ion. Finally, he deg ee o au oma ion sugges s ha i is wo h using ou app oach wi h ega d o he effo equi ed o gene a e and in oduce he cus omized FQAs models in o a so wa e a chi ec u e. Howe e , we need o comple e he e alua ion wi h empi ical s udies in o de o e idence he benefi s and use ulness o ou app oach. Despi e he benefi s o using he echniques and ools o SPLs and CVL in pa icula , we ha e also iden ified some sho comings o ou app oach. A possible disad an age is ha he SA has o deal wi h many models. Howe e , we need o ake in o accoun ha some o hese models a e jus configu a ions o he o he s (e.g. he esolu ion mod- els), o he s a e au oma ically gene a ed by CVL (e.g. he esol ed models), and o he s a e defined only once and a e eusable in o he applica ions (e.g. he FQAs base model and he FQAs a iabili y model). Ano he disad an age o ou app oach is ha he wea ing ules implemen ed as model- o-model ans o ma ions in he las s age o ou app oach depend on he me a-model used o speci y he co e so wa e a chi ec u e. This means ha hese ules will need o be adap ed o edefined i he SA decides o use a so wa e a chi ec u al model ha , in spi e o being MOF-dependen , does no inco po a e he same me a-model cons uc o s ha we used o define he wea ing ules. This is howe e a mino limi a ion in he sense ha ou app oach enables he in eg a ion o diffe en model- o- model ans o ma ions as pa o he wea ing s ep, by using he ex ension mechanism p o ided by CVL (i.e. he OVPs). Also no e ha e en i he wea ing ules need o be adap ed,