scieee Science in your language
[en] (orig)

An Aspect-Oriented Model Transformation to Weave Security using CVL

Abstract

In this paper, we combine the Common Variability Language (CVL) and the ATL Transformation Language to customize and incorporate a generic security model into any application that requires security. Security spans a large set of concerns such as integrity, encryption or authentication, among others, and each concern needs to be incorporated into the base application in a different way and at different points of the application. We propose a set of weaving patterns using model transformations in ATL to automatically weave the security concerns with the base application in an aspect-oriented way. Since different applications require different security requirements, the security model needs to be customized before its incorporation into the application. We resolve the variability of the security properties and implement the weaving process in CVL. We use an e-voting case study to illustrate our proposal using the CVL approach.

Read accessible full text

An Aspect-Oriented Model Transformation to Weave Security using CVL

Author: Horcas Aguilera, José Miguel; Pinto, Mónica; Fuentes, Lidia
Publisher: IEEE Computer Society
Year: 2014
Source: https://idus.us.es/bitstreams/44d56340-ac54-4e5f-a30c-02c242a51a9b/download
An Aspec -O ien ed Model T ans o ma ion o Wea e Secu i y using CVL
Jose-Miguel Ho cas, M´
onica Pin o and Lidia Fuen es
CAOSD G oup, Depa amen o de Lenguajes y Ciencias de la Compu aci´
on, Uni e si y o M´
alaga, M´
alaga, Spain
{ho cas, pin o, l }@lcc.uma.es
Keywo ds: Aspec -O ien a ion, ATL, CVL, Model T ans o ma ions, Secu i y, Va iabili y, Wea ing Pa e n.
Abs ac : In his pape , we combine he Common Va iabili y Language (CVL) and he ATL T ans o ma ion Language
o cus omize and inco po a e a gene ic secu i y model in o any applica ion ha equi es secu i y. Secu i y
spans a la ge se o conce ns such as in eg i y, enc yp ion o au hen ica ion, among o he s, and each conce n
needs o be inco po a ed in o he base applica ion in a di e en way and a di e en poin s o he applica ion.
We p opose a se o wea ing pa e ns using model ans o ma ions in ATL o au oma ically wea e he secu i y
conce ns wi h he base applica ion in an aspec -o ien ed way. Since di e en applica ions equi e di e en
secu i y equi emen s, he secu i y model needs o be cus omized be o e i s inco po a ion in o he applica ion.
We esol e he a iabili y o he secu i y p ope ies and implemen he wea ing p ocess in CVL. We use an
e- o ing case s udy o illus a e ou p oposal using he CVL app oach.
1 INTRODUCTION
In Componen -Based So wa e Enginee ing (CBSE),
he e a e p ope ies o an applica ion ha can be dis-
pe sed and eplica ed in se e al modules. Secu i y
is an example o hese p ope ies, which a e usu-
ally de ined in mul iple di e en componen s c oss-
cu ing he base unc ionali y o he applica ion. Fo
ins ance, access con ol is de ined in each compo-
nen ha needs o con ol he use igh s o use a e-
sou ce. An Aspec -O ien ed (AO) app oach aims o
achie e sepa a ion o c osscu ing conce ns and ad-
d esses he limi a ion o he adi ional so wa e ech-
nologies (e.g. CBSE, Objec -O ien ed P og amming)
o app op ia ely modula ize c osscu ing conce ns a
he di e en de elopmen s ages. F om he pe spec-
i e o AO, secu i y is a c osscu ing conce n he be-
ha io o which is angled and/o sca e ed wi h he
co e beha io o he applica ion being a ec ed by i .
Modeling secu i y sepa a ely om he a ec ed ap-
plica ion has many ad an ages: high eusabili y, low
coupled componen s, high cohesi e so wa e a chi-
ec u es. To bene i om hese ad an ages secu i y e-
qui emen s need o be aken in o accoun om ea ly
s ages in he de elopmen p ocess — i.e. a he a -
chi ec u al le el. Mo eo e , he so wa e a chi ec u e
modeling he secu i y unc ionali y should be de ined
sepa a ely om he so wa e a chi ec u e o he base
applica ions ha need i . Sepa a ing secu i y ela ed
conce ns om he applica ion base code is also he
main mo i a ion o he INTER-TRUST p ojec 1 ha
is unde de elopmen . Wi h his p ojec , he indus ial
pa ne s demand secu i y solu ions easily ins an iable
as pa o any applica ion. The app oach p esen ed in
his pape pu sues an answe o hese demands. How-
e e , secu i y spans a la ge se o conce ns, including
enc yp ion, au hen ica ion, access con ol, and au ho-
iza ion, among o he s, and each o hese conce ns
a ec s he base applica ion in a di e en way. Fo
ins ance, access con ol is pe o med be o e he exe-
cu ion o a es ic ed ac ion by he use , while enc yp-
ion is pe o med be o e sending a message h ough a
ne wo k in o de o enc yp he in o ma ion, bu also
a e ecei ing he message in he a ge in o de o de-
c yp he in o ma ion. Mo eo e , no all he applica-
ions equi e all he secu i y conce ns. A i s applica-
ion may equi e he in eg i y and he non- epudia ion
conce ns, a second applica ion may equi e only he
enc yp ion conce n, and a hi d applica ion may also
equi e he enc yp ion conce n bu using a di e en
enc yp ion algo i hm. The so wa e a chi ec u e o
hese applica ions should include only he necessa y
secu i y unc ionali y and he conce ns ha a e no
equi ed should no be pa o he inal a chi ec u e
o he applica ion.
In his pape , we ollow an Aspec -O ien ed Mod-
eling (AOM) app oach2 o inco po a e (wea e in he
AO e minology) a cus omized secu i y model in o a
1h p://www.in e - us .eu//
2h p://www.aspec -modeling.o g
base applica ion ha has been speci ied independen ly
— i.e. he applica ion does no con ain any secu-
i y conce n and he secu i y model has been de ined
gene ically in o de o euse i in se e al applica ions.
This is done au oma ically wi hou manually modi y-
ing he exis ing elemen s in he model o he base ap-
plica ion. To do his, we use he Common Va iabili y
Language (CVL) (Haugen e al., 2012) in combina-
ion wi h he ATL T ans o ma ion Language (Jouaul
e al., 2008). CVL allows us o speci y and esol e he
a iabili y o he secu i y model, and also allows us o
wea e he cus omized secu i y model wi h he base
applica ion using model ans o ma ion ules, au o-
ma ically gene a ing he comple e model o he appli-
ca ion wi h he secu i y unc ionali y. CVL includes
he possibili y o delega ing i s con ol du ing a i-
abili y esolu ion o a Model-2-Model (M2M) ans-
o ma ion engine such as ATL, QVT (Que y/View/-
T ans o ma ion), e c. The main con ibu ion o his
pape is ha we de ine a se o eusable wea ing pa -
e ns in CVL o inco po a e each secu i y conce n in
he mos sui able place (join poin ) o he base appli-
ca ion model. We de ine he seman ic o each wea -
ing pa e n using eusable ATL ans o ma ion ules
ha a e di e en o each secu i y conce n since each
o hem need o be wo en wi h he base applica ion in
a di e en way.
The ad an age o using CVL is ha i allows us
o de ine he models in any language based on Me a-
Objec Facili y (MOF) me a-models. In his pape we
use he Uni ied Modeling Language (UML) o de ine
he models (so wa e a chi ec u es as componen dia-
g ams) and he wea ing pa e ns, bu ou p oposal is
sui able o use wi h any MOF complian language,
and he wea ing pa e ns a e eusable by de ining a
p e ious model ans o ma ion be ween UML and he
language used o de ine he applica ion and he se-
cu i y so wa e a chi ec u es. In addi ion, he secu-
i y so wa e a chi ec u e can also be eused wi h any
o he applica ion o he same domain by eusing he
model ans o ma ions.
In con as o o he a iabili y echniques used by
adi ional So wa e P oduc Lines (SPLs), such as
ea u e models ha equi e an addi ional p ocess o
gene a e he cus omized so wa e a chi ec u e om
he ea u e model con igu a ion, CVL is in ended o
be used in conjunc ion wi h a chi ec u al models, e-
sol ing he a iabili y and gene a ing he a chi ec-
u al con igu a ion in he same p ocess. Fu he mo e,
CVL was submi ed o he Objec Managemen G oup
(OMG) as s anda d o model a iabili y.
The es o his pape is s uc u ed as ollows. In
Sec ion 2 we p esen he case s udy used h oughou
he pape . Sec ion 3 in oduces ou p oposal using
CVL and b ie ly desc ibes he CVL e minology. Sec-
ion 4 explains how we pe o m he con igu a ion o
he secu i y model and he wea ing p ocess. In Sec-
ion 5 we p o ide he wea ing pa e ns o he secu i y
conce ns h ough model ans o ma ions. Sec ion 6
su eys ela ed wo k and in Sec ion 7 we conclude
he pape and conside u u e di ec ions.
2 CASE STUDY
Ou case s udy is an elec onic o ing (e- o ing) ap-
plica ion which is one o he demons a o s o he
INTER-TRUST p ojec . E-Vo ing is one o he en-
i onmen s whe e secu i y equi emen s a e complex.
Figu e 1 shows a simpli ied so wa e a chi ec u e in
UML wi h he main unc ionali y o an e- o ing ap-
plica ion. This a chi ec u e does no include any com-
ponen ela ed o he secu i y equi emen s. The Vo e
Applica ion componen allows clien s o cas hei
o es om sma phones, able s, e-mails, e c. by us-
ing he EVo ingIn in e ace. The Vo e Se e com-
ponen ecei es he o es and he Elec ion Da a s o es
hem in a digi al ballo box h ough he Vo eS o ageIn
in e ace. Adminis a o s can manage he elec ion
da a and ge he elec ion esul s h ough he Vo ingM-
ngIn in e ace ha p o ides access o he unc ional-
i y o he Elec ion Da a and he Vo e Coun ing compo-
nen s.
Apa om he base unc ionali y shown in Fig-
u e 1, he e- o ing applica ion equi es a lis o se-
cu i y ex a- unc ional p ope ies. Conc e ely, i is o
pa amoun impo ance o gua an ee ha : (1) all he
o es in he digi al ballo box belong o an eligible
o e (i.e. in eg i y o he o es); (2) a he same ime
he p i acy o he o e mus be p ese ed, e en in
he coun ing p ocess (i.e. o es mus be p o ec ed by
means o c yp og aphy); (3) he o e mus be au-
hen ica ed using a pe sonal digi al ce i ica e, such
an elec onic ID ca d, and (4) adminis a o s mus be
au ho ized o pe o m ac ions o e he elec ion da a.
Wi h he goal o de ining he secu i y unc ionali-
ies once, and eusing hem o se e al applica ions,
Figu e 2 shows a UML so wa e a chi ec u e wi h
he comple e unc ionali y o all he possible secu i y
conce ns. This includes he In eg i y,Au hen ica ion,
Enc yp ion,Au ho iza ion, and Digi al Signa u e com-
ponen s wi h all kinds o au hen ica ion mechanisms,
enc yp ion algo i hms, and he in eg i y, au ho iza-
ion, and digi al signa u e unc ionali y.3Howe e ,
3To simpli y he case s udy we do no show all he ex-
is ing secu i y p ope ies no all he exis ing algo i hms o
each conce n.
Figu e 1: e-Vo ing so wa e a chi ec u e.
Figu e 2: Secu i y so wa e a chi ec u e.
he e- o ing applica ion only needs a pa icula con-
igu a ion o hese secu i y unc ionali ies based on
he p e ious secu i y equi emen s.
3 OUR PROPOSAL USING CVL
CVL is a domain-independen language o speci y-
ing and esol ing a iabili y. I makes he speci ica-
ion and esolu ion o a iabili y o e any ins ance o
models de ined using a MOF-based me a-model eas-
ie .
Figu e 3 shows ou p oposal using he CVL ap-
p oach. The co e so wa e a chi ec u e o ou base ap-
plica ion and he secu i y so wa e a chi ec u e wi h
all he secu i y unc ionali ies a e he Base Models
and can be de ined in any MOF-de ined language.
The speci ica ion o he a iabili y o he secu i y
conce ns is exp essed in an abs ac le el in he Va i-
abili y Model. The speci ica ion o conc e e a iabili y
in he secu i y model and he secu i y wea ing pa -
e ns o each secu i y conce n a e also de ined in he
a iabili y model. Di e en con igu a ions o he se-
cu i y model a e p o ided in he Resolu ion Models.
These con igu a ions a e selec ions o a se o choices
in he a iabili y model.
CVL p o ides an execu able engine o au oma i-
cally p oduce he Resol ed Models aking as inpu s
he a iabili y model, he esolu ion models and he
base models. In ou p oposal, he esol ed models
a e he so wa e a chi ec u e o he base applica ion
Figu e 3: Ou p oposal using he CVL app oach.
wo en wi h he eques ed secu i y con igu a ion. The
p ocess o de i ing a esol ed model om a base
model gi en a esolu ion model is called ma e ializa-
ion. Apa om esol ing a iabili y, he CVL en-
gine also has he capabili y o delega e i s con ol o a
M2M ans o ma ion engine. This is especially use ul
o de ining domain speci ic ac ions he seman ics o
which a e no de ined by CVL, and i is used in ou
p oposal o implemen he wea ing p ocess be ween
he applica ion a chi ec u e and he secu i y con igu-
a ion a chi ec u e by pe o ming models ans o ma-
ions du ing he execu ion o CVL.
In o de o implemen ou p oposal we use he ol-
lowing concep s o CVL4:
Va iabili y Speci ica ions (VSpecs). They a e pa
o he a iabili y model. They a e ee-based
s uc u es ep esen ing choices,5and can ha e
a ia ion poin s bound o hem. To ma e ialize a
base model wi h a a iabili y model o e i , eso-
lu ions o he VSpecs mus be p o ided. Choices
a e esol ed by deciding hem nega i ely o posi-
i ely.
Va ia ion Poin s. They a e pa o he a iabili y
model and de ine speci ic modi ica ions o be ap-
plied o he base model du ing ma e ializa ion.
They e e o base model elemen s ia base mod-
els handles and a e bound o VSpecs. The appli-
ca ion o he a ia ion poin s depends on he eso-
lu ion o he VSpecs.
Exis ence Va ia ion Poin . I is a kind o a ia ion
poin ha indica es he exis ence o a pa icula
objec , link, o alue in he base model. I s neg-
a i e applica ion in ol es dele ing elemen s om
he base model.
Opaque Va ia ion Poin (OVP). I is a kind o a i-
a ion poin he impac o which on he base model
is use -de ined h ough a model ans o ma ion
language. OVPs allow ex ending and cus omizing
he seman ic o he exis ing CVL a ia ion poin s.
4The comple e desc ip ion o CVL can be ound in
h p://www.omgwiki.o g/ a iabili y/.
5“Fea u es” in mos SPL app oaches.
The AO main concep s ha we use a e:
Join Poin . I is a poin in he model (e.g. a me hod
call in an in e ace) which can be a ec ed by he
c osscu ing beha io .
Ad ice. I is he addi ional beha io ha a ec s he
base p og am a he selec ed join poin s. The e
a e usually h ee kinds o ad ices based on ‘when’
he beha io akes place in e e ence o he join
poin s: be o e,a e , and a ound. A ound ad-
ices allow bypassing he execu ion o he cap-
u ed join poin s.
Poin cu . I is an exp ession ha desc ibes a se o
join poin s.
4 SECURITY WEAVING
In o de o inco po a e a pa icula con igu a ion o
he secu i y unc ionali y in o he base applica ion o
ou case s udy, we implemen he wea ing p ocess us-
ing CVL and, conc e ely, using he OVPs o CVL. Be-
o e ha , we need o cus omize he secu i y so wa e
a chi ec u e om he secu i y equi emen s o ou e-
o ing applica ion. Bo h p ocesses, he selec ion o a
secu i y con igu a ion and he wea ing a e pe o med
in he same s ep using CVL.
Figu e 4 shows an ins ance o ou p oposal us-
ing he CVL app oach wi h ou case s udy and he
secu i y speci ica ions. The a iabili y model o se-
cu i y is speci ied in an abs ac le el using VSpecs
( op o Figu e 4). Secu i y p ope ies a e decomposed
in o choices in he VSpecs, indica ing which secu-
i y conce ns a e op ional and which a e manda o y.
In ou case s udy, o simplici y, secu i y is decom-
posed only in o he choices o In eg i y,Access Con-
ol which in u n con ains he Au hen ica ion and Au-
ho iza ion conce ns, and C yp og aphy ha con ains
he Enc yp ion and Digi al Signa u e conce ns. Each
o hem is also composed by he a ailable me hods
and algo i hms. Fo ins ance, he e a e h ee kinds o
me hods o e i y he in eg i y o he da a: Passwo d
e i ica ion,Da a iden i ie , and Hash e i ica ion. The
las one can be pe o med by using he MD5 o he
SHA-1 algo i hm. The esolu ion o all hese choices
equi e a yes/no decision, and he secu i y con igu a-
ion ( he esolu ion model) is a selec ion o his se o
choices in he VSpecs — i.e. he secu i y conce ns
ha a e decided posi i ely (da kened choices in Fig-
u e 4).
The conc e e a iabili y o secu i y and he wea -
ing pa e ns a e speci ied using a ia ion poin s (mid-
dle o Figu e 4): “objec exis ence” a ia ion poin s
o ealize he a iabili y and OVPs o do he wea -
Figu e 4: Secu i y con igu ing and wea ing using CVL.
ing. The objec exis ence a ia ion poin s a e bound o
choices o he VSpecs and e e o componen s o he
secu i y so wa e a chi ec u e (bo om o Figu e 4).
This kind o a ia ion poin indica es he exis ence o
a pa icula objec (componen ) ha will be included
o emo ed om he secu i y so wa e a chi ec u e
based on he esolu ion p o ided o he associa ed
VSpec. Fo ins ance, he a ia ion poin bound o
he In eg i y conce n in he VSpecs (:Objec Exis ence)
indica es ha i he In eg i y choice is decided posi-
i ely (i.e. is selec ed in he esolu ion model) in a
con igu a ion, he ela ed elemen s ( he In eg i y com-
ponen and i s in e aces wi h hei a achmen s) in
he secu i y so wa e a chi ec u e will exis in he e-
sol ed model and i in eg i y is decided nega i ely
(i.e. is no selec ed in he esolu ion model) hose
ela ed elemen s will be emo ed om he esol ed
model.
The OVPs a e also bound o he VSpecs bu ha e
wo o mo e e e ences in he base models: (1) one
e e ence (sou ce objec s) o he in e ace in he secu-
i y so wa e a chi ec u e he beha io o which we
wan o inco po a e in ou base applica ion — i.e.
he ad ice, and (2) one o mo e e e ences ( a ge
objec s) o he in e aces in he applica ion so wa e
a chi ec u e whe e we wan o inco po a e he secu-
i y conce n — i.e. he join poin s. Fo ins ance,
OVP2 has a e e ence (sou ceObjec ) o he Enc yp-
ionIn in e ace in he secu i y model and wo a ge s
( a ge Objec s): one o enc yp ing ( ha e e ences
o he E o ingIn in e ace in he applica ion model)
and one o dec yp ing ( ha e e ences o he Vo ing-
Da aIn in e ace).
OVPs a e also bound o an OVPType, whe e his
ype explici ly de ines he seman ic o he special sub-
s i u ion — i.e. he ans o ma ion ules o wea e he
secu i y conce ns in o he base applica ion. Each se-
cu i y conce n needs o be wo en wi h he base ap-
plica ion ollowing a di e en ans o ma ion pa e n
based on he aspec ual in o ma ion o he conce n: he

kind o he ad ice ha he conce n implemen s: be-
o e,a e , o a ound; he me hod (ad ice) ha mus
be execu ed by he conce n; and he in e cep ed me h-
ods (join poin s) in he base applica ion. So, using
CVL we need o use se e al a ia ion poin s, wi h
di e en seman ics, o indica e how he elemen s o
he models a e adap ed in o de o gene a e he e-
sol ed model. Du ing a iabili y ma e ializa ion, he
CVL engine will delega e i s con ol o a M2M ans-
o ma ion engine (ATL in ou p oposal) whene e i
encoun e s an OVP. The M2M ans o ma ion engine
execu es he seman ic speci ica ion associa ed wi h
he OVP and esol es he a iabili y acco dingly.
The esol ed model is au oma ically gene a ed
(Figu e 5) and he secu i y con igu a ion is wo en
wi h ou applica ion so wa e a chi ec u e: he com-
ponen s ela ed o he secu i y conce ns a e clea ly
isible in he s a ic pa o he a chi ec u e, and he
ela ionships be ween he secu i y elemen s and he
elemen s o he base applica ion (“c osscu s” depen-
dency ela ionship) explici ly indica e ha he sou ces
o he ela ionships c osscu he a chi ec u al le el,
and he a ge s a e he poin o he applica ion whe e
hey ake place. Howe e , he aspec ual in o ma ion
wi h he in e ac ions be ween he componen s is no
ep esen ed in he so wa e a chi ec u e o Figu e 5.
To comple e he design we complemen he so wa e
a chi ec u e wi h a se o sequence diag ams ha ep-
esen he aspec ual in o ma ion and ha a e also au-
oma ically gene a ed by he wea ing pa e ns (Pin o
e al., 2009). The ollowing sec ion shows he wea -
ing pa e ns, in de ail, o each secu i y conce n.
5 SECURITY WEAVING
PATTERNS
The na u e o each secu i y conce n a oids ha ing o
ha e a unique and homogeneous wea ing pa e n. As
we explained in he p e ious sec ion each conce n
needs di e en aspec ual in o ma ion and he wea -
ing pa e ns (i.e. he ans o ma ion ules) needed o
pe o m he wea ing a e di e en .
The seman ic speci ica ion associa ed wi h each
OVP mus include ans o ma ion ules o: (1) in-
co po a e he secu i y componen s in o he so wa e
a chi ec u e o he base applica ion; (2) c ea e he
“c osscu s” ela ionships be ween he in e ace o he
conce n ( he ad ice) and he in e ace o he applica-
ion whe e he c osscu s ake places ( he join poin );
and (3) gene a e he sequence diag am ha ep esen s
he beha io o he c osscu ing ela ionship.
We de ine a se o ATL ans o ma ions o each
o he secu i y conce ns: au hen ica ion, enc yp ion,
au ho iza ion, in eg i y, and digi al signa u e. Wea -
ing pa e ns o o he secu i y o c osscu ing con-
ce ns may be de ined in a simila way. To pe o m
he wea ing be ween he models, each ATL ans o -
ma ion akes as inpu he wo models ( he applica ion
model and he secu i y model) and gene a es as ou pu
he same applica ion model wi h he app op ia e secu-
i y conce n me ged. The elemen s o he applica ion
model emain unchanged in he ou pu model. So, we
can ocus on he gene a ion o he secu i y elemen s
in he ATL ans o ma ions.
The ans o ma ion ules (wea ing pa e ns) a e
de ined only once and can be eused in each appli-
ca ion. Howe e , he e is speci ic in o ma ion o he
base applica ion ha he so wa e a chi ec mus p o-
ide because i is di e en o each applica ion. Fo
ins ance, he so wa e a chi ec mus de ine he con-
c e e poin cu s (e.g. he me hod signa u e) o he
join poin s in he base applica ion. To simpli y he
case s udy, we only use me hod call/execu ion poin -
cu designa o s. In o de o make he ans o ma ion
ules mo e eusable, we de ine he aspec ual in o ma-
ion as a ibu es (helpe s) in ATL ha mus be illed
in o each applica ion wi h he signa u e o he in e -
cep ed me hod by he c osscu ela ionship.
5.1 Au hen ica ion
The seman ic o he special subs i u ion o he au-
hen ica ion conce n is shown in he Lis ing 1. The
ans o ma ion ule: (1) copies he au hen ica ion se-
cu i y elemen s: he componen (sou ceComp) and
in e ace (sou ceIn ) om he Secu i yModel o he
applica ion model (AppModel in he ule); (2) c e-
a es he “c osscu ” ela ionship be ween he sou ce
(sou ceIn ) and he a ge ( a ge In ) in e aces; and
(3) gene a es he sequence diag am wi h he in e ac-
ions be ween he au hen ica ion and he base applica-
ion elemen s.
The aspec ual in o ma ion is coded in he ans-
o ma ion pa e n and is used o gene a e he in e -
ac ions. Fo ins ance, o gene a e he au hen ica ion
sequence diag am we use a called ule o ATL wi h
he aspec ual in o ma ion: he in e cep ed me hod
o e(Objec ) (p o ided wi h he helpe ope a ion), he
ad ice (‘au hen ica e()’), and he kind o he ad ice
(‘a ound’), apa om he in e aces and componen s
ela ed.
The sequence diag am gene a ed is shown in
Figu e 6. Au hen ica ion is usually pe o med be o e
a me hod call, howe e we use an a ound ad ice in
o de o abo he call o he me hod o e(Objec ) i
he au hen ica ion ails.
Figu e 5: Applica ion wi h secu i y unc ionali y wo en.
Lis ing 1: Seman icSpec1 (SpecialSubs i u ionAu hen)
module au hen ica ion;
c ea e OUT : U ML om AppModel:UML,
Sec u i yMod el : UML ;
ule Au hen ica ion {
om so u ce In : UML ! In e ace in Secu i yModel ,
sou ceC omp : UML ! Compo nen in Secu i yModel ,
a g e In : UML ! In e ace in AppModel ,
( so u ceIn . name = ‘ Au hen ica ionIn ’ and
sou c eCom p . na me = ‘ A u h en ic a ion ’ a nd
a ge In . nam e = hisModule. a ge O bjec )
o sec u i yC om p : UML ! Co mp on en ( ... ) ,
sec u i yIn : UML ! In e ac e (... ) ,
c o ss cu A ss oc : UML ! D ep ende ncy (
clien <- sou ceIn ,
supplie <- a ge In , ...)
do {c osscu Assoc.applyS e eo ype(
hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ;
hisModule. C e a eAu hI n e ac i on ( a ge In ,
sou ceIn , sou ceComp , ‘a ound ’,
hisModule. o pe a i on , ‘ a u h en i ca e () ’) ;}
}
5.2 Enc yp ion
The seman ic o he special subs i u ion o he en-
c yp ion conce n (Lis ing 2) is di e en since i
uses wo di e en ad ices (‘enc yp (Objec )’ and ‘de-
c yp (Objec )’) in wo di e en poin s o he appli-
ca ion. The o es a e enc yp ed in he o e(Objec )
me hod o he EVo ingIn in e ace (p o ided by
he ope Enc yp helpe ), and a e dec yp ed in he
ge Vo e() me hod o he Vo ingDa aIn in e ace (p o-
Figu e 6: Au hen ica ion sequence diag am.
ided by he ope Dec yp helpe ). The ans o ma ion
ule au oma ically gene a es wo di e en sequence
diag ams wi h ha in o ma ion: one o enc yp ing
(Figu e 7) and one o dec yp ing (Figu e 8).
Lis ing 2: Seman icSpec2 (SpecialSubs i u ionEnc yp )
module enc yp ion ;
c ea e OUT : U ML om AppModel:UML,
Sec u i yMod el : UML ;
ule Enc yp ion {
om so u ce In : UML ! In e ace in Secu i yModel ,
sou c eC omp : UML ! Compo nen in Secu i yModel ,
a ge E nc y pIn : UM L ! In e ace in AppModel ,
a ge D ec y pIn : UM L ! In e ace in AppModel ,
( so u ceIn . name = ‘ Enc yp ionIn ’ and
s ou c eC om p . n ame = ‘ E nc yp io n ’ an d
a ge D ec ypI n . name = hisModule.
a ge Obje c 1 and
a ge E nc y p In . name = hisModule.
a ge Obje c 2 )
o sec u i yC om p : UML ! Co mp on en ( ... ) ,
sec u i yIn : UML ! In e ac e (... ) ,
c o ss cu A ss oc1 : UML ! D epen denc y (
clien <- sou ceIn ,
supplie <- a ge Enc yp In , ...),
c o ss cu A ss oc2 : UML ! D epen denc y (
clien <- sou ceIn ,
supplie <- a ge Dec yp In , ...)
do {c osscu Assoc1.applyS e eo ype(
hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ;
c osscu Assoc2.applyS e eo ype(
hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ;
hisModule. C ea eEn c yp In e ac ion (
a ge Enc yp In , sou ceIn , sou ceComp ,
‘a ound ’, hisModule.ope Enc yp ,
‘ enc yp ( Objec ) ’);
hisModule. C ea eEn c yp In e ac ion (
a ge Dec yp In , sou ceIn ,
sou ceComp , ‘ a ound ’,
hisModule.ope Dec yp ,
‘ dec yp ( Objec ) ’) ;}
}
Figu e 7: Enc yp ion sequence diag am o enc yp ing.
Figu e 8: Enc yp ion sequence diag am o dec yp ing.
5.3 Digi al Signa u e
The wea ing pa e n o he digi al signa u e conce n
is e y simila o he enc yp ion pa e n, bu we only
need he ‘sign(Objec )’ ad ice. We use an a e ad ice
o sign he o es in he se e side a e sending hem
in o de o p e en de ice clien s wi h lowe esou ces
om cas ing hei o es. The sequence diag am o
Figu e 9 shows ha he ad ice ‘sign(Objec )’ is pe -
o med a e he execu ion o he me hod o e(Objec ).
Figu e 9: Digi al signa u e sequence diag am.
5.4 In eg i y
The in eg i y conce n gua an ees he o es belong o
an eligible o e . The wea ing pa e n is also simila
o he enc yp ion pa e n. We use an a ound ad ice
o e he me hod s o eVo e(Objec ) o he Vo ingS o -
eIn in e ace wi h he pu pose o e i ying he au-
hen ici y o he o e and ejec ing i i he o e be-
longs o an in alid o e (see he sequence diag am o
Figu e 10).
Figu e 10: In eg i y sequence diag am.
5.5 Au ho iza ion
The au ho iza ion wea ing pa e n is simila o he au-
hen ica ion case, and in mos secu i y app oaches he
au ho iza ion conce n is based on di e en au hen i-
ca ion mechanisms. In ou e- o ing applica ion we
use a be o e ad ice in o de o g an o deny pe mis-
sions o access p i ileged da a o he elec ion p ocess.
The sequence diag am (Figu e 11) shows ha he au-
ho iza ion logic e i ies he pe missions o he ad-
minis a o be o e calling any me hod o he Vo ingM-
ngIn in e ace.
6 RELATED WORK
Secu i y is usually achie ed in se e al ways, bu mos
o he app oaches p esen he secu i y as a se o non-
Figu e 11: Au ho iza ion sequence diag am.
unc ional p ope ies, ins ead o ocusing on he unc-
ional pa o he secu i y conce ns as we do. Fo in-
s ance, in (Geo g e al., 2002), he au ho s analyze he
impac o secu i y p ope ies on o he unc ional con-
ce ns o he base applica ion using an AO app oach.
Model D i en Enginee ing (MDE) has also been
used in he ield o SPLs (Sij ema, 2010). Sij ema
p oposes a s a egy o le ATL handle he a iabili y
by ex ending he conc e e syn ax o ATL wi h he con-
cep o a iabili y ules. Va iabili y ules a e used in
he con ex o a ans o ma ion sequence which suc-
cessi ely e ines models. Howe e , hey i s model
he a iabili y sepa a ely in a ea u e diag am and
ha e o make he co espondence be ween he ea u e
selec ions and he ealiza ion o he a e ac s. In com-
pa ison wi h ou p oposal, using CVL we model he
a iabili y and bind he ea u es di ec ly o he ele-
men s in he so wa e a chi ec u e. We use he basic
ATL wi hou he need o ex end i , bu ou p oposal
can also be used wi h o he ans o ma ion languages
such as QVT o ETL (Epsilon T ans o ma ion Lan-
guage) (Kolo os e al., 2008).
Recen ly, CVL has been applied in mul iple ap-
p oaches. Fo ins ance, CVL is used o manage
he a iabili y in he con ex o so wa e p ocesses
(Rouill´
e e al., 2012), business p ocess (Ayo a e al.,
2012), o e en o syn hesizing an SPL using model
compa ison (Zhang e al., 2011). In (Combemale
e al., 2012) CVL is used o speci y and esol e he
a iabili y o a so wa e design, and he Reusable
Aspec Model (RAM) echnique is used o speci y
and compose he de ailed s uc u al and beha io al
design models co esponding o he chosen a ian s.
Ou app oach, in con as , ocuses on he a chi ec u al
le el in he de elopmen p ocess, and we pe o m he
wea ing p ocess wi h he CVL engine, ins ead o us-
ing an ex e nal RAM wea e .
7 CONCLUSIONS AND FUTURE
WORK
We ha e de ined a se o secu i y wea ing pa e ns
h ough model ans o ma ions in ATL ha allows
he au oma ic inco po a ion o a cus omized secu i y
model in o he base applica ion model by using CVL
and AOSD. CVL makes ou p oposal sui able o use
wi h any MOF based model. We ha e implemen ed
ou p oposal and used i wi h se e al case s udies such
as he e- o ing applica ion p esen ed in his pape o
in a ehicle- o- ehicle and ehicle- o-in as uc u e
applica ion ha is ano he o he demons a o s o he
INTER-TRUST p ojec . In all cases, we ha e used
UML as he modeling language o he so wa e a chi-
ec u es and we conclude ha ou p oposal imp o es
he modula i y and eusabili y o bo h so wa e a chi-
ec u es, he co e a chi ec u e o he applica ion and
he secu i y so wa e a chi ec u e.
As pa o ou u u e wo k, we plan o make he
ans o ma ion ules mo e eusable by using a hi d
binding model in he wea ing pa e ns (Du ´
an e al.,
2013). The binding model allows de ining he aspec-
ual in o ma ion (e.g. poin cu de ini ions, ad ices)
as ex e nal pa ame e s o use hem in he ans o ma-
ion ules independen ly om he inpu models. We
also plan o ake in o accoun he exis ing dependen-
cies be ween he secu i y conce ns (e.g. au hen ica-
ion is usually needed by he au ho iza ion conce n),
and how hese dependencies a ec he wea ing pa -
e ns and he sequence diag ams when wo o mo e
conce ns a e applied in he same poin o he appli-
ca ion. Mo eo e , we plan o de ine wea ing pa e ns
o o he c osscu ing conce ns such as usabili y, pe -
sis ence, con ex -awa eness, e c.
ACKNOWLEDGEMENTS
Wo k suppo ed by he Eu opean P ojec INTER-
TRUST 317731 and he Spanish P ojec s TIN2012-
34840 and FamiWa e P09-TIC-5231.
REFERENCES
Ayo a, C., To es, V., Pelechano, V., and Al ´
e ez, G. H.
(2012). Applying CVL o business p ocess a iabil-
i y managemen . In P oceedings o he VARiabili y
o You Wo kshop: Va iabili y Modeling Made Use-
ul o E e yone, VARY ’12, pages 26–31, New Yo k,
NY, USA. ACM.
Combemale, B., Ba ais, O., Alam, O., and Kienzle, J.
(2012). Using CVL o Ope a ionalize P oduc Line