scieee Open visual document viewer

An Aspect-Oriented Model Transformation to Weave Security using CVL

Horcas Aguilera, José Miguel; Pinto, Mónica; Fuentes, Lidia

Abstract

In this paper, we combine the Common Variability Language (CVL) and the ATL Transformation Language to customize and incorporate a generic security model into any application that requires security. Security spans a large set of concerns such as integrity, encryption or authentication, among others, and each concern needs to be incorporated into the base application in a different way and at different points of the application. We propose a set of weaving patterns using model transformations in ATL to automatically weave the security concerns with the base application in an aspect-oriented way. Since different applications require different security requirements, the security model needs to be customized before its incorporation into the application. We resolve the variability of the security properties and implement the weaving process in CVL. We use an e-voting case study to illustrate our proposal using the CVL approach.

Full text

An Aspec -O ien ed Model T ans o ma ion o Wea e Secu i y using CVL Jose-Miguel Ho cas, M´ onica Pin o and Lidia Fuen es CAOSD G oup, Depa amen o de Lenguajes y Ciencias de la Compu aci´ on, Uni e si y o M´ alaga, M´ alaga, Spain {ho cas, pin o, l }@lcc.uma.es Keywo ds: Aspec -O ien a ion, ATL, CVL, Model T ans o ma ions, Secu i y, Va iabili y, Wea ing Pa e n. Abs ac : In his pape , we combine he Common Va iabili y Language (CVL) and he ATL T ans o ma ion Language o cus omize and inco po a e a gene ic secu i y model in o any applica ion ha equi es secu i y. Secu i y spans a la ge se o conce ns such as in eg i y, enc yp ion o au hen ica ion, among o he s, and each conce n needs o be inco po a ed in o he base applica ion in a di e en way and a di e en poin s o he applica ion. We p opose a se o wea ing pa e ns using model ans o ma ions in ATL o au oma ically wea e he secu i y conce ns wi h he base applica ion in an aspec -o ien ed way. Since di e en applica ions equi e di e en secu i y equi emen s, he secu i y model needs o be cus omized be o e i s inco po a ion in o he applica ion. We esol e he a iabili y o he secu i y p ope ies and implemen he wea ing p ocess in CVL. We use an e- o ing case s udy o illus a e ou p oposal using he CVL app oach. 1 INTRODUCTION In Componen -Based So wa e Enginee ing (CBSE), he e a e p ope ies o an applica ion ha can be dis- pe sed and eplica ed in se e al modules. Secu i y is an example o hese p ope ies, which a e usu- ally de ined in mul iple di e en componen s c oss- cu ing he base unc ionali y o he applica ion. Fo ins ance, access con ol is de ined in each compo- nen ha needs o con ol he use igh s o use a e- sou ce. An Aspec -O ien ed (AO) app oach aims o achie e sepa a ion o c osscu ing conce ns and ad- d esses he limi a ion o he adi ional so wa e ech- nologies (e.g. CBSE, Objec -O ien ed P og amming) o app op ia ely modula ize c osscu ing conce ns a he di e en de elopmen s ages. F om he pe spec- i e o AO, secu i y is a c osscu ing conce n he be- ha io o which is angled and/o sca e ed wi h he co e beha io o he applica ion being a ec ed by i . Modeling secu i y sepa a ely om he a ec ed ap- plica ion has many ad an ages: high eusabili y, low coupled componen s, high cohesi e so wa e a chi- ec u es. To bene i om hese ad an ages secu i y e- qui emen s need o be aken in o accoun om ea ly s ages in he de elopmen p ocess — i.e. a he a - chi ec u al le el. Mo eo e , he so wa e a chi ec u e modeling he secu i y unc ionali y should be de ined sepa a ely om he so wa e a chi ec u e o he base applica ions ha need i . Sepa a ing secu i y ela ed conce ns om he applica ion base code is also he main mo i a ion o he INTER-TRUST p ojec 1 ha is unde de elopmen . Wi h his p ojec , he indus ial pa ne s demand secu i y solu ions easily ins an iable as pa o any applica ion. The app oach p esen ed in his pape pu sues an answe o hese demands. How- e e , secu i y spans a la ge se o conce ns, including enc yp ion, au hen ica ion, access con ol, and au ho- iza ion, among o he s, and each o hese conce ns a ec s he base applica ion in a di e en way. Fo ins ance, access con ol is pe o med be o e he exe- cu ion o a es ic ed ac ion by he use , while enc yp- ion is pe o med be o e sending a message h ough a ne wo k in o de o enc yp he in o ma ion, bu also a e ecei ing he message in he a ge in o de o de- c yp he in o ma ion. Mo eo e , no all he applica- ions equi e all he secu i y conce ns. A i s applica- ion may equi e he in eg i y and he non- epudia ion conce ns, a second applica ion may equi e only he enc yp ion conce n, and a hi d applica ion may also equi e he enc yp ion conce n bu using a di e en enc yp ion algo i hm. The so wa e a chi ec u e o hese applica ions should include only he necessa y secu i y unc ionali y and he conce ns ha a e no equi ed should no be pa o he inal a chi ec u e o he applica ion. In his pape , we ollow an Aspec -O ien ed Mod- eling (AOM) app oach2 o inco po a e (wea e in he AO e minology) a cus omized secu i y model in o a 1h p://www.in e - us .eu// 2h p://www.aspec -modeling.o g base applica ion ha has been speci ied independen ly — i.e. he applica ion does no con ain any secu- i y conce n and he secu i y model has been de ined gene ically in o de o euse i in se e al applica ions. This is done au oma ically wi hou manually modi y- ing he exis ing elemen s in he model o he base ap- plica ion. To do his, we use he Common Va iabili y Language (CVL) (Haugen e al., 2012) in combina- ion wi h he ATL T ans o ma ion Language (Jouaul e al., 2008). CVL allows us o speci y and esol e he a iabili y o he secu i y model, and also allows us o wea e he cus omized secu i y model wi h he base applica ion using model ans o ma ion ules, au o- ma ically gene a ing he comple e model o he appli- ca ion wi h he secu i y unc ionali y. CVL includes he possibili y o delega ing i s con ol du ing a i- abili y esolu ion o a Model-2-Model (M2M) ans- o ma ion engine such as ATL, QVT (Que y/View/- T ans o ma ion), e c. The main con ibu ion o his pape is ha we de ine a se o eusable wea ing pa - e ns in CVL o inco po a e each secu i y conce n in he mos sui able place (join poin ) o he base appli- ca ion model. We de ine he seman ic o each wea - ing pa e n using eusable ATL ans o ma ion ules ha a e di e en o each secu i y conce n since each o hem need o be wo en wi h he base applica ion in a di e en way. The ad an age o using CVL is ha i allows us o de ine he models in any language based on Me a- Objec Facili y (MOF) me a-models. In his pape we use he Uni ied Modeling Language (UML) o de ine he models (so wa e a chi ec u es as componen dia- g ams) and he wea ing pa e ns, bu ou p oposal is sui able o use wi h any MOF complian language, and he wea ing pa e ns a e eusable by de ining a p e ious model ans o ma ion be ween UML and he language used o de ine he applica ion and he se- cu i y so wa e a chi ec u es. In addi ion, he secu- i y so wa e a chi ec u e can also be eused wi h any o he applica ion o he same domain by eusing he model ans o ma ions. In con as o o he a iabili y echniques used by adi ional So wa e P oduc Lines (SPLs), such as ea u e models ha equi e an addi ional p ocess o gene a e he cus omized so wa e a chi ec u e om he ea u e model con igu a ion, CVL is in ended o be used in conjunc ion wi h a chi ec u al models, e- sol ing he a iabili y and gene a ing he a chi ec- u al con igu a ion in he same p ocess. Fu he mo e, CVL was submi ed o he Objec Managemen G oup (OMG) as s anda d o model a iabili y. The es o his pape is s uc u ed as ollows. In Sec ion 2 we p esen he case s udy used h oughou he pape . Sec ion 3 in oduces ou p oposal using CVL and b ie ly desc ibes he CVL e minology. Sec- ion 4 explains how we pe o m he con igu a ion o he secu i y model and he wea ing p ocess. In Sec- ion 5 we p o ide he wea ing pa e ns o he secu i y conce ns h ough model ans o ma ions. Sec ion 6 su eys ela ed wo k and in Sec ion 7 we conclude he pape and conside u u e di ec ions. 2 CASE STUDY Ou case s udy is an elec onic o ing (e- o ing) ap- plica ion which is one o he demons a o s o he INTER-TRUST p ojec . E-Vo ing is one o he en- i onmen s whe e secu i y equi emen s a e complex. Figu e 1 shows a simpli ied so wa e a chi ec u e in UML wi h he main unc ionali y o an e- o ing ap- plica ion. This a chi ec u e does no include any com- ponen ela ed o he secu i y equi emen s. The Vo e Applica ion componen allows clien s o cas hei o es om sma phones, able s, e-mails, e c. by us- ing he EVo ingIn in e ace. The Vo e Se e com- ponen ecei es he o es and he Elec ion Da a s o es hem in a digi al ballo box h ough he Vo eS o ageIn in e ace. Adminis a o s can manage he elec ion da a and ge he elec ion esul s h ough he Vo ingM- ngIn in e ace ha p o ides access o he unc ional- i y o he Elec ion Da a and he Vo e Coun ing compo- nen s. Apa om he base unc ionali y shown in Fig- u e 1, he e- o ing applica ion equi es a lis o se- cu i y ex a- unc ional p ope ies. Conc e ely, i is o pa amoun impo ance o gua an ee ha : (1) all he o es in he digi al ballo box belong o an eligible o e (i.e. in eg i y o he o es); (2) a he same ime he p i acy o he o e mus be p ese ed, e en in he coun ing p ocess (i.e. o es mus be p o ec ed by means o c yp og aphy); (3) he o e mus be au- hen ica ed using a pe sonal digi al ce i ica e, such an elec onic ID ca d, and (4) adminis a o s mus be au ho ized o pe o m ac ions o e he elec ion da a. Wi h he goal o de ining he secu i y unc ionali- ies once, and eusing hem o se e al applica ions, Figu e 2 shows a UML so wa e a chi ec u e wi h he comple e unc ionali y o all he possible secu i y conce ns. This includes he In eg i y,Au hen ica ion, Enc yp ion,Au ho iza ion, and Digi al Signa u e com- ponen s wi h all kinds o au hen ica ion mechanisms, enc yp ion algo i hms, and he in eg i y, au ho iza- ion, and digi al signa u e unc ionali y.3Howe e , 3To simpli y he case s udy we do no show all he ex- is ing secu i y p ope ies no all he exis ing algo i hms o each conce n. Figu e 1: e-Vo ing so wa e a chi ec u e. Figu e 2: Secu i y so wa e a chi ec u e. he e- o ing applica ion only needs a pa icula con- igu a ion o hese secu i y unc ionali ies based on he p e ious secu i y equi emen s. 3 OUR PROPOSAL USING CVL CVL is a domain-independen language o speci y- ing and esol ing a iabili y. I makes he speci ica- ion and esolu ion o a iabili y o e any ins ance o models de ined using a MOF-based me a-model eas- ie . Figu e 3 shows ou p oposal using he CVL ap- p oach. The co e so wa e a chi ec u e o ou base ap- plica ion and he secu i y so wa e a chi ec u e wi h all he secu i y unc ionali ies a e he Base Models and can be de ined in any MOF-de ined language. The speci ica ion o he a iabili y o he secu i y conce ns is exp essed in an abs ac le el in he Va i- abili y Model. The speci ica ion o conc e e a iabili y in he secu i y model and he secu i y wea ing pa - e ns o each secu i y conce n a e also de ined in he a iabili y model. Di e en con igu a ions o he se- cu i y model a e p o ided in he Resolu ion Models. These con igu a ions a e selec ions o a se o choices in he a iabili y model. CVL p o ides an execu able engine o au oma i- cally p oduce he Resol ed Models aking as inpu s he a iabili y model, he esolu ion models and he base models. In ou p oposal, he esol ed models a e he so wa e a chi ec u e o he base applica ion Figu e 3: Ou p oposal using he CVL app oach. wo en wi h he eques ed secu i y con igu a ion. The p ocess o de i ing a esol ed model om a base model gi en a esolu ion model is called ma e ializa- ion. Apa om esol ing a iabili y, he CVL en- gine also has he capabili y o delega e i s con ol o a M2M ans o ma ion engine. This is especially use ul o de ining domain speci ic ac ions he seman ics o which a e no de ined by CVL, and i is used in ou p oposal o implemen he wea ing p ocess be ween he applica ion a chi ec u e and he secu i y con igu- a ion a chi ec u e by pe o ming models ans o ma- ions du ing he execu ion o CVL. In o de o implemen ou p oposal we use he ol- lowing concep s o CVL4: Va iabili y Speci ica ions (VSpecs). They a e pa o he a iabili y model. They a e ee-based s uc u es ep esen ing choices,5and can ha e a ia ion poin s bound o hem. To ma e ialize a base model wi h a a iabili y model o e i , eso- lu ions o he VSpecs mus be p o ided. Choices a e esol ed by deciding hem nega i ely o posi- i ely. Va ia ion Poin s. They a e pa o he a iabili y model and de ine speci ic modi ica ions o be ap- plied o he base model du ing ma e ializa ion. They e e o base model elemen s ia base mod- els handles and a e bound o VSpecs. The appli- ca ion o he a ia ion poin s depends on he eso- lu ion o he VSpecs. Exis ence Va ia ion Poin . I is a kind o a ia ion poin ha indica es he exis ence o a pa icula objec , link, o alue in he base model. I s neg- a i e applica ion in ol es dele ing elemen s om he base model. Opaque Va ia ion Poin (OVP). I is a kind o a i- a ion poin he impac o which on he base model is use -de ined h ough a model ans o ma ion language. OVPs allow ex ending and cus omizing he seman ic o he exis ing CVL a ia ion poin s. 4The comple e desc ip ion o CVL can be ound in h p://www.omgwiki.o g/ a iabili y/. 5“Fea u es” in mos SPL app oaches. The AO main concep s ha we use a e: Join Poin . I is a poin in he model (e.g. a me hod call in an in e ace) which can be a ec ed by he c osscu ing beha io . Ad ice. I is he addi ional beha io ha a ec s he base p og am a he selec ed join poin s. The e a e usually h ee kinds o ad ices based on ‘when’ he beha io akes place in e e ence o he join poin s: be o e,a e , and a ound. A ound ad- ices allow bypassing he execu ion o he cap- u ed join poin s. Poin cu . I is an exp ession ha desc ibes a se o join poin s. 4 SECURITY WEAVING In o de o inco po a e a pa icula con igu a ion o he secu i y unc ionali y in o he base applica ion o ou case s udy, we implemen he wea ing p ocess us- ing CVL and, conc e ely, using he OVPs o CVL. Be- o e ha , we need o cus omize he secu i y so wa e a chi ec u e om he secu i y equi emen s o ou e- o ing applica ion. Bo h p ocesses, he selec ion o a secu i y con igu a ion and he wea ing a e pe o med in he same s ep using CVL. Figu e 4 shows an ins ance o ou p oposal us- ing he CVL app oach wi h ou case s udy and he secu i y speci ica ions. The a iabili y model o se- cu i y is speci ied in an abs ac le el using VSpecs ( op o Figu e 4). Secu i y p ope ies a e decomposed in o choices in he VSpecs, indica ing which secu- i y conce ns a e op ional and which a e manda o y. In ou case s udy, o simplici y, secu i y is decom- posed only in o he choices o In eg i y,Access Con- ol which in u n con ains he Au hen ica ion and Au- ho iza ion conce ns, and C yp og aphy ha con ains he Enc yp ion and Digi al Signa u e conce ns. Each o hem is also composed by he a ailable me hods and algo i hms. Fo ins ance, he e a e h ee kinds o me hods o e i y he in eg i y o he da a: Passwo d e i ica ion,Da a iden i ie , and Hash e i ica ion. The las one can be pe o med by using he MD5 o he SHA-1 algo i hm. The esolu ion o all hese choices equi e a yes/no decision, and he secu i y con igu a- ion ( he esolu ion model) is a selec ion o his se o choices in he VSpecs — i.e. he secu i y conce ns ha a e decided posi i ely (da kened choices in Fig- u e 4). The conc e e a iabili y o secu i y and he wea - ing pa e ns a e speci ied using a ia ion poin s (mid- dle o Figu e 4): “objec exis ence” a ia ion poin s o ealize he a iabili y and OVPs o do he wea - Figu e 4: Secu i y con igu ing and wea ing using CVL. ing. The objec exis ence a ia ion poin s a e bound o choices o he VSpecs and e e o componen s o he secu i y so wa e a chi ec u e (bo om o Figu e 4). This kind o a ia ion poin indica es he exis ence o a pa icula objec (componen ) ha will be included o emo ed om he secu i y so wa e a chi ec u e based on he esolu ion p o ided o he associa ed VSpec. Fo ins ance, he a ia ion poin bound o he In eg i y conce n in he VSpecs (:Objec Exis ence) indica es ha i he In eg i y choice is decided posi- i ely (i.e. is selec ed in he esolu ion model) in a con igu a ion, he ela ed elemen s ( he In eg i y com- ponen and i s in e aces wi h hei a achmen s) in he secu i y so wa e a chi ec u e will exis in he e- sol ed model and i in eg i y is decided nega i ely (i.e. is no selec ed in he esolu ion model) hose ela ed elemen s will be emo ed om he esol ed model. The OVPs a e also bound o he VSpecs bu ha e wo o mo e e e ences in he base models: (1) one e e ence (sou ce objec s) o he in e ace in he secu- i y so wa e a chi ec u e he beha io o which we wan o inco po a e in ou base applica ion — i.e. he ad ice, and (2) one o mo e e e ences ( a ge objec s) o he in e aces in he applica ion so wa e a chi ec u e whe e we wan o inco po a e he secu- i y conce n — i.e. he join poin s. Fo ins ance, OVP2 has a e e ence (sou ceObjec ) o he Enc yp- ionIn in e ace in he secu i y model and wo a ge s ( a ge Objec s): one o enc yp ing ( ha e e ences o he E o ingIn in e ace in he applica ion model) and one o dec yp ing ( ha e e ences o he Vo ing- Da aIn in e ace). OVPs a e also bound o an OVPType, whe e his ype explici ly de ines he seman ic o he special sub- s i u ion — i.e. he ans o ma ion ules o wea e he secu i y conce ns in o he base applica ion. Each se- cu i y conce n needs o be wo en wi h he base ap- plica ion ollowing a di e en ans o ma ion pa e n based on he aspec ual in o ma ion o he conce n: he kind o he ad ice ha he conce n implemen s: be- o e,a e , o a ound; he me hod (ad ice) ha mus be execu ed by he conce n; and he in e cep ed me h- ods (join poin s) in he base applica ion. So, using CVL we need o use se e al a ia ion poin s, wi h di e en seman ics, o indica e how he elemen s o he models a e adap ed in o de o gene a e he e- sol ed model. Du ing a iabili y ma e ializa ion, he CVL engine will delega e i s con ol o a M2M ans- o ma ion engine (ATL in ou p oposal) whene e i encoun e s an OVP. The M2M ans o ma ion engine execu es he seman ic speci ica ion associa ed wi h he OVP and esol es he a iabili y acco dingly. The esol ed model is au oma ically gene a ed (Figu e 5) and he secu i y con igu a ion is wo en wi h ou applica ion so wa e a chi ec u e: he com- ponen s ela ed o he secu i y conce ns a e clea ly isible in he s a ic pa o he a chi ec u e, and he ela ionships be ween he secu i y elemen s and he elemen s o he base applica ion (“c osscu s” depen- dency ela ionship) explici ly indica e ha he sou ces o he ela ionships c osscu he a chi ec u al le el, and he a ge s a e he poin o he applica ion whe e hey ake place. Howe e , he aspec ual in o ma ion wi h he in e ac ions be ween he componen s is no ep esen ed in he so wa e a chi ec u e o Figu e 5. To comple e he design we complemen he so wa e a chi ec u e wi h a se o sequence diag ams ha ep- esen he aspec ual in o ma ion and ha a e also au- oma ically gene a ed by he wea ing pa e ns (Pin o e al., 2009). The ollowing sec ion shows he wea - ing pa e ns, in de ail, o each secu i y conce n. 5 SECURITY WEAVING PATTERNS The na u e o each secu i y conce n a oids ha ing o ha e a unique and homogeneous wea ing pa e n. As we explained in he p e ious sec ion each conce n needs di e en aspec ual in o ma ion and he wea - ing pa e ns (i.e. he ans o ma ion ules) needed o pe o m he wea ing a e di e en . The seman ic speci ica ion associa ed wi h each OVP mus include ans o ma ion ules o: (1) in- co po a e he secu i y componen s in o he so wa e a chi ec u e o he base applica ion; (2) c ea e he “c osscu s” ela ionships be ween he in e ace o he conce n ( he ad ice) and he in e ace o he applica- ion whe e he c osscu s ake places ( he join poin ); and (3) gene a e he sequence diag am ha ep esen s he beha io o he c osscu ing ela ionship. We de ine a se o ATL ans o ma ions o each o he secu i y conce ns: au hen ica ion, enc yp ion, au ho iza ion, in eg i y, and digi al signa u e. Wea - ing pa e ns o o he secu i y o c osscu ing con- ce ns may be de ined in a simila way. To pe o m he wea ing be ween he models, each ATL ans o - ma ion akes as inpu he wo models ( he applica ion model and he secu i y model) and gene a es as ou pu he same applica ion model wi h he app op ia e secu- i y conce n me ged. The elemen s o he applica ion model emain unchanged in he ou pu model. So, we can ocus on he gene a ion o he secu i y elemen s in he ATL ans o ma ions. The ans o ma ion ules (wea ing pa e ns) a e de ined only once and can be eused in each appli- ca ion. Howe e , he e is speci ic in o ma ion o he base applica ion ha he so wa e a chi ec mus p o- ide because i is di e en o each applica ion. Fo ins ance, he so wa e a chi ec mus de ine he con- c e e poin cu s (e.g. he me hod signa u e) o he join poin s in he base applica ion. To simpli y he case s udy, we only use me hod call/execu ion poin - cu designa o s. In o de o make he ans o ma ion ules mo e eusable, we de ine he aspec ual in o ma- ion as a ibu es (helpe s) in ATL ha mus be illed in o each applica ion wi h he signa u e o he in e - cep ed me hod by he c osscu ela ionship. 5.1 Au hen ica ion The seman ic o he special subs i u ion o he au- hen ica ion conce n is shown in he Lis ing 1. The ans o ma ion ule: (1) copies he au hen ica ion se- cu i y elemen s: he componen (sou ceComp) and in e ace (sou ceIn ) om he Secu i yModel o he applica ion model (AppModel in he ule); (2) c e- a es he “c osscu ” ela ionship be ween he sou ce (sou ceIn ) and he a ge ( a ge In ) in e aces; and (3) gene a es he sequence diag am wi h he in e ac- ions be ween he au hen ica ion and he base applica- ion elemen s. The aspec ual in o ma ion is coded in he ans- o ma ion pa e n and is used o gene a e he in e - ac ions. Fo ins ance, o gene a e he au hen ica ion sequence diag am we use a called ule o ATL wi h he aspec ual in o ma ion: he in e cep ed me hod o e(Objec ) (p o ided wi h he helpe ope a ion), he ad ice (‘au hen ica e()’), and he kind o he ad ice (‘a ound’), apa om he in e aces and componen s ela ed. The sequence diag am gene a ed is shown in Figu e 6. Au hen ica ion is usually pe o med be o e a me hod call, howe e we use an a ound ad ice in o de o abo he call o he me hod o e(Objec ) i he au hen ica ion ails. Figu e 5: Applica ion wi h secu i y unc ionali y wo en. Lis ing 1: Seman icSpec1 (SpecialSubs i u ionAu hen) module au hen ica ion; c ea e OUT : U ML om AppModel:UML, Sec u i yMod el : UML ; ule Au hen ica ion { om so u ce In : UML ! In e ace in Secu i yModel , sou ceC omp : UML ! Compo nen in Secu i yModel , a g e In : UML ! In e ace in AppModel , ( so u ceIn . name = ‘ Au hen ica ionIn ’ and sou c eCom p . na me = ‘ A u h en ic a ion ’ a nd a ge In . nam e = hisModule. a ge O bjec ) o sec u i yC om p : UML ! Co mp on en ( ... ) , sec u i yIn : UML ! In e ac e (... ) , c o ss cu A ss oc : UML ! D ep ende ncy ( clien <- sou ceIn , supplie <- a ge In , ...) do {c osscu Assoc.applyS e eo ype( hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ; hisModule. C e a eAu hI n e ac i on ( a ge In , sou ceIn , sou ceComp , ‘a ound ’, hisModule. o pe a i on , ‘ a u h en i ca e () ’) ;} } 5.2 Enc yp ion The seman ic o he special subs i u ion o he en- c yp ion conce n (Lis ing 2) is di e en since i uses wo di e en ad ices (‘enc yp (Objec )’ and ‘de- c yp (Objec )’) in wo di e en poin s o he appli- ca ion. The o es a e enc yp ed in he o e(Objec ) me hod o he EVo ingIn in e ace (p o ided by he ope Enc yp helpe ), and a e dec yp ed in he ge Vo e() me hod o he Vo ingDa aIn in e ace (p o- Figu e 6: Au hen ica ion sequence diag am. ided by he ope Dec yp helpe ). The ans o ma ion ule au oma ically gene a es wo di e en sequence diag ams wi h ha in o ma ion: one o enc yp ing (Figu e 7) and one o dec yp ing (Figu e 8). Lis ing 2: Seman icSpec2 (SpecialSubs i u ionEnc yp ) module enc yp ion ; c ea e OUT : U ML om AppModel:UML, Sec u i yMod el : UML ; ule Enc yp ion { om so u ce In : UML ! In e ace in Secu i yModel , sou c eC omp : UML ! Compo nen in Secu i yModel , a ge E nc y pIn : UM L ! In e ace in AppModel , a ge D ec y pIn : UM L ! In e ace in AppModel , ( so u ceIn . name = ‘ Enc yp ionIn ’ and s ou c eC om p . n ame = ‘ E nc yp io n ’ an d a ge D ec ypI n . name = hisModule. a ge Obje c 1 and a ge E nc y p In . name = hisModule. a ge Obje c 2 ) o sec u i yC om p : UML ! Co mp on en ( ... ) , sec u i yIn : UML ! In e ac e (... ) , c o ss cu A ss oc1 : UML ! D epen denc y ( clien <- sou ceIn , supplie <- a ge Enc yp In , ...), c o ss cu A ss oc2 : UML ! D epen denc y ( clien <- sou ceIn , supplie <- a ge Dec yp In , ...) do {c osscu Assoc1.applyS e eo ype( hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ; c osscu Assoc2.applyS e eo ype( hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ; hisModule. C ea eEn c yp In e ac ion ( a ge Enc yp In , sou ceIn , sou ceComp , ‘a ound ’, hisModule.ope Enc yp , ‘ enc yp ( Objec ) ’); hisModule. C ea eEn c yp In e ac ion ( a ge Dec yp In , sou ceIn , sou ceComp , ‘ a ound ’, hisModule.ope Dec yp , ‘ dec yp ( Objec ) ’) ;} } Figu e 7: Enc yp ion sequence diag am o enc yp ing. Figu e 8: Enc yp ion sequence diag am o dec yp ing. 5.3 Digi al Signa u e The wea ing pa e n o he digi al signa u e conce n is e y simila o he enc yp ion pa e n, bu we only need he ‘sign(Objec )’ ad ice. We use an a e ad ice o sign he o es in he se e side a e sending hem in o de o p e en de ice clien s wi h lowe esou ces om cas ing hei o es. The sequence diag am o Figu e 9 shows ha he ad ice ‘sign(Objec )’ is pe - o med a e he execu ion o he me hod o e(Objec ). Figu e 9: Digi al signa u e sequence diag am. 5.4 In eg i y The in eg i y conce n gua an ees he o es belong o an eligible o e . The wea ing pa e n is also simila o he enc yp ion pa e n. We use an a ound ad ice o e he me hod s o eVo e(Objec ) o he Vo ingS o - eIn in e ace wi h he pu pose o e i ying he au- hen ici y o he o e and ejec ing i i he o e be- longs o an in alid o e (see he sequence diag am o Figu e 10). Figu e 10: In eg i y sequence diag am. 5.5 Au ho iza ion The au ho iza ion wea ing pa e n is simila o he au- hen ica ion case, and in mos secu i y app oaches he au ho iza ion conce n is based on di e en au hen i- ca ion mechanisms. In ou e- o ing applica ion we use a be o e ad ice in o de o g an o deny pe mis- sions o access p i ileged da a o he elec ion p ocess. The sequence diag am (Figu e 11) shows ha he au- ho iza ion logic e i ies he pe missions o he ad- minis a o be o e calling any me hod o he Vo ingM- ngIn in e ace. 6 RELATED WORK Secu i y is usually achie ed in se e al ways, bu mos o he app oaches p esen he secu i y as a se o non- Figu e 11: Au ho iza ion sequence diag am. unc ional p ope ies, ins ead o ocusing on he unc- ional pa o he secu i y conce ns as we do. Fo in- s ance, in (Geo g e al., 2002), he au ho s analyze he impac o secu i y p ope ies on o he unc ional con- ce ns o he base applica ion using an AO app oach. Model D i en Enginee ing (MDE) has also been used in he ield o SPLs (Sij ema, 2010). Sij ema p oposes a s a egy o le ATL handle he a iabili y by ex ending he conc e e syn ax o ATL wi h he con- cep o a iabili y ules. Va iabili y ules a e used in he con ex o a ans o ma ion sequence which suc- cessi ely e ines models. Howe e , hey i s model he a iabili y sepa a ely in a ea u e diag am and ha e o make he co espondence be ween he ea u e selec ions and he ealiza ion o he a e ac s. In com- pa ison wi h ou p oposal, using CVL we model he a iabili y and bind he ea u es di ec ly o he ele- men s in he so wa e a chi ec u e. We use he basic ATL wi hou he need o ex end i , bu ou p oposal can also be used wi h o he ans o ma ion languages such as QVT o ETL (Epsilon T ans o ma ion Lan- guage) (Kolo os e al., 2008). Recen ly, CVL has been applied in mul iple ap- p oaches. Fo ins ance, CVL is used o manage he a iabili y in he con ex o so wa e p ocesses (Rouill´ e e al., 2012), business p ocess (Ayo a e al., 2012), o e en o syn hesizing an SPL using model compa ison (Zhang e al., 2011). In (Combemale e al., 2012) CVL is used o speci y and esol e he a iabili y o a so wa e design, and he Reusable Aspec Model (RAM) echnique is used o speci y and compose he de ailed s uc u al and beha io al design models co esponding o he chosen a ian s. Ou app oach, in con as , ocuses on he a chi ec u al le el in he de elopmen p ocess, and we pe o m he wea ing p ocess wi h he CVL engine, ins ead o us- ing an ex e nal RAM wea e . 7 CONCLUSIONS AND FUTURE WORK We ha e de ined a se o secu i y wea ing pa e ns h ough model ans o ma ions in ATL ha allows he au oma ic inco po a ion o a cus omized secu i y model in o he base applica ion model by using CVL and AOSD. CVL makes ou p oposal sui able o use wi h any MOF based model. We ha e implemen ed ou p oposal and used i wi h se e al case s udies such as he e- o ing applica ion p esen ed in his pape o in a ehicle- o- ehicle and ehicle- o-in as uc u e applica ion ha is ano he o he demons a o s o he INTER-TRUST p ojec . In all cases, we ha e used UML as he modeling language o he so wa e a chi- ec u es and we conclude ha ou p oposal imp o es he modula i y and eusabili y o bo h so wa e a chi- ec u es, he co e a chi ec u e o he applica ion and he secu i y so wa e a chi ec u e. As pa o ou u u e wo k, we plan o make he ans o ma ion ules mo e eusable by using a hi d binding model in he wea ing pa e ns (Du ´ an e al., 2013). The binding model allows de ining he aspec- ual in o ma ion (e.g. poin cu de ini ions, ad ices) as ex e nal pa ame e s o use hem in he ans o ma- ion ules independen ly om he inpu models. We also plan o ake in o accoun he exis ing dependen- cies be ween he secu i y conce ns (e.g. au hen ica- ion is usually needed by he au ho iza ion conce n), and how hese dependencies a ec he wea ing pa - e ns and he sequence diag ams when wo o mo e conce ns a e applied in he same poin o he appli- ca ion. Mo eo e , we plan o de ine wea ing pa e ns o o he c osscu ing conce ns such as usabili y, pe - sis ence, con ex -awa eness, e c. ACKNOWLEDGEMENTS Wo k suppo ed by he Eu opean P ojec INTER- TRUST 317731 and he Spanish P ojec s TIN2012- 34840 and FamiWa e P09-TIC-5231. REFERENCES Ayo a, C., To es, V., Pelechano, V., and Al ´ e ez, G. H. (2012). Applying CVL o business p ocess a iabil- i y managemen . In P oceedings o he VARiabili y o You Wo kshop: Va iabili y Modeling Made Use- ul o E e yone, VARY ’12, pages 26–31, New Yo k, NY, USA. ACM. Combemale, B., Ba ais, O., Alam, O., and Kienzle, J. (2012). Using CVL o Ope a ionalize P oduc Line