An Aspec -O ien ed Model T ans o ma ion o Wea e Secu i y using CVL
Jose-Miguel Ho cas, M´
onica Pin o and Lidia Fuen es
CAOSD G oup, Depa amen o de Lenguajes y Ciencias de la Compu aci´
on, Uni e si y o M´
alaga, M´
alaga, Spain
{ho cas, pin o, l }@lcc.uma.es
Keywo ds: Aspec -O ien a ion, ATL, CVL, Model T ans o ma ions, Secu i y, Va iabili y, Wea ing Pa e n.
Abs ac : In his pape , we combine he Common Va iabili y Language (CVL) and he ATL T ans o ma ion Language
o cus omize and inco po a e a gene ic secu i y model in o any applica ion ha equi es secu i y. Secu i y
spans a la ge se o conce ns such as in eg i y, enc yp ion o au hen ica ion, among o he s, and each conce n
needs o be inco po a ed in o he base applica ion in a di e en way and a di e en poin s o he applica ion.
We p opose a se o wea ing pa e ns using model ans o ma ions in ATL o au oma ically wea e he secu i y
conce ns wi h he base applica ion in an aspec -o ien ed way. Since di e en applica ions equi e di e en
secu i y equi emen s, he secu i y model needs o be cus omized be o e i s inco po a ion in o he applica ion.
We esol e he a iabili y o he secu i y p ope ies and implemen he wea ing p ocess in CVL. We use an
e- o ing case s udy o illus a e ou p oposal using he CVL app oach.
1 INTRODUCTION
In Componen -Based So wa e Enginee ing (CBSE),
he e a e p ope ies o an applica ion ha can be dis-
pe sed and eplica ed in se e al modules. Secu i y
is an example o hese p ope ies, which a e usu-
ally de ined in mul iple di e en componen s c oss-
cu ing he base unc ionali y o he applica ion. Fo
ins ance, access con ol is de ined in each compo-
nen ha needs o con ol he use igh s o use a e-
sou ce. An Aspec -O ien ed (AO) app oach aims o
achie e sepa a ion o c osscu ing conce ns and ad-
d esses he limi a ion o he adi ional so wa e ech-
nologies (e.g. CBSE, Objec -O ien ed P og amming)
o app op ia ely modula ize c osscu ing conce ns a
he di e en de elopmen s ages. F om he pe spec-
i e o AO, secu i y is a c osscu ing conce n he be-
ha io o which is angled and/o sca e ed wi h he
co e beha io o he applica ion being a ec ed by i .
Modeling secu i y sepa a ely om he a ec ed ap-
plica ion has many ad an ages: high eusabili y, low
coupled componen s, high cohesi e so wa e a chi-
ec u es. To bene i om hese ad an ages secu i y e-
qui emen s need o be aken in o accoun om ea ly
s ages in he de elopmen p ocess — i.e. a he a -
chi ec u al le el. Mo eo e , he so wa e a chi ec u e
modeling he secu i y unc ionali y should be de ined
sepa a ely om he so wa e a chi ec u e o he base
applica ions ha need i . Sepa a ing secu i y ela ed
conce ns om he applica ion base code is also he
main mo i a ion o he INTER-TRUST p ojec 1 ha
is unde de elopmen . Wi h his p ojec , he indus ial
pa ne s demand secu i y solu ions easily ins an iable
as pa o any applica ion. The app oach p esen ed in
his pape pu sues an answe o hese demands. How-
e e , secu i y spans a la ge se o conce ns, including
enc yp ion, au hen ica ion, access con ol, and au ho-
iza ion, among o he s, and each o hese conce ns
a ec s he base applica ion in a di e en way. Fo
ins ance, access con ol is pe o med be o e he exe-
cu ion o a es ic ed ac ion by he use , while enc yp-
ion is pe o med be o e sending a message h ough a
ne wo k in o de o enc yp he in o ma ion, bu also
a e ecei ing he message in he a ge in o de o de-
c yp he in o ma ion. Mo eo e , no all he applica-
ions equi e all he secu i y conce ns. A i s applica-
ion may equi e he in eg i y and he non- epudia ion
conce ns, a second applica ion may equi e only he
enc yp ion conce n, and a hi d applica ion may also
equi e he enc yp ion conce n bu using a di e en
enc yp ion algo i hm. The so wa e a chi ec u e o
hese applica ions should include only he necessa y
secu i y unc ionali y and he conce ns ha a e no
equi ed should no be pa o he inal a chi ec u e
o he applica ion.
In his pape , we ollow an Aspec -O ien ed Mod-
eling (AOM) app oach2 o inco po a e (wea e in he
AO e minology) a cus omized secu i y model in o a
1h p://www.in e - us .eu//
2h p://www.aspec -modeling.o g
base applica ion ha has been speci ied independen ly
— i.e. he applica ion does no con ain any secu-
i y conce n and he secu i y model has been de ined
gene ically in o de o euse i in se e al applica ions.
This is done au oma ically wi hou manually modi y-
ing he exis ing elemen s in he model o he base ap-
plica ion. To do his, we use he Common Va iabili y
Language (CVL) (Haugen e al., 2012) in combina-
ion wi h he ATL T ans o ma ion Language (Jouaul
e al., 2008). CVL allows us o speci y and esol e he
a iabili y o he secu i y model, and also allows us o
wea e he cus omized secu i y model wi h he base
applica ion using model ans o ma ion ules, au o-
ma ically gene a ing he comple e model o he appli-
ca ion wi h he secu i y unc ionali y. CVL includes
he possibili y o delega ing i s con ol du ing a i-
abili y esolu ion o a Model-2-Model (M2M) ans-
o ma ion engine such as ATL, QVT (Que y/View/-
T ans o ma ion), e c. The main con ibu ion o his
pape is ha we de ine a se o eusable wea ing pa -
e ns in CVL o inco po a e each secu i y conce n in
he mos sui able place (join poin ) o he base appli-
ca ion model. We de ine he seman ic o each wea -
ing pa e n using eusable ATL ans o ma ion ules
ha a e di e en o each secu i y conce n since each
o hem need o be wo en wi h he base applica ion in
a di e en way.
The ad an age o using CVL is ha i allows us
o de ine he models in any language based on Me a-
Objec Facili y (MOF) me a-models. In his pape we
use he Uni ied Modeling Language (UML) o de ine
he models (so wa e a chi ec u es as componen dia-
g ams) and he wea ing pa e ns, bu ou p oposal is
sui able o use wi h any MOF complian language,
and he wea ing pa e ns a e eusable by de ining a
p e ious model ans o ma ion be ween UML and he
language used o de ine he applica ion and he se-
cu i y so wa e a chi ec u es. In addi ion, he secu-
i y so wa e a chi ec u e can also be eused wi h any
o he applica ion o he same domain by eusing he
model ans o ma ions.
In con as o o he a iabili y echniques used by
adi ional So wa e P oduc Lines (SPLs), such as
ea u e models ha equi e an addi ional p ocess o
gene a e he cus omized so wa e a chi ec u e om
he ea u e model con igu a ion, CVL is in ended o
be used in conjunc ion wi h a chi ec u al models, e-
sol ing he a iabili y and gene a ing he a chi ec-
u al con igu a ion in he same p ocess. Fu he mo e,
CVL was submi ed o he Objec Managemen G oup
(OMG) as s anda d o model a iabili y.
The es o his pape is s uc u ed as ollows. In
Sec ion 2 we p esen he case s udy used h oughou
he pape . Sec ion 3 in oduces ou p oposal using
CVL and b ie ly desc ibes he CVL e minology. Sec-
ion 4 explains how we pe o m he con igu a ion o
he secu i y model and he wea ing p ocess. In Sec-
ion 5 we p o ide he wea ing pa e ns o he secu i y
conce ns h ough model ans o ma ions. Sec ion 6
su eys ela ed wo k and in Sec ion 7 we conclude
he pape and conside u u e di ec ions.
2 CASE STUDY
Ou case s udy is an elec onic o ing (e- o ing) ap-
plica ion which is one o he demons a o s o he
INTER-TRUST p ojec . E-Vo ing is one o he en-
i onmen s whe e secu i y equi emen s a e complex.
Figu e 1 shows a simpli ied so wa e a chi ec u e in
UML wi h he main unc ionali y o an e- o ing ap-
plica ion. This a chi ec u e does no include any com-
ponen ela ed o he secu i y equi emen s. The Vo e
Applica ion componen allows clien s o cas hei
o es om sma phones, able s, e-mails, e c. by us-
ing he EVo ingIn in e ace. The Vo e Se e com-
ponen ecei es he o es and he Elec ion Da a s o es
hem in a digi al ballo box h ough he Vo eS o ageIn
in e ace. Adminis a o s can manage he elec ion
da a and ge he elec ion esul s h ough he Vo ingM-
ngIn in e ace ha p o ides access o he unc ional-
i y o he Elec ion Da a and he Vo e Coun ing compo-
nen s.
Apa om he base unc ionali y shown in Fig-
u e 1, he e- o ing applica ion equi es a lis o se-
cu i y ex a- unc ional p ope ies. Conc e ely, i is o
pa amoun impo ance o gua an ee ha : (1) all he
o es in he digi al ballo box belong o an eligible
o e (i.e. in eg i y o he o es); (2) a he same ime
he p i acy o he o e mus be p ese ed, e en in
he coun ing p ocess (i.e. o es mus be p o ec ed by
means o c yp og aphy); (3) he o e mus be au-
hen ica ed using a pe sonal digi al ce i ica e, such
an elec onic ID ca d, and (4) adminis a o s mus be
au ho ized o pe o m ac ions o e he elec ion da a.
Wi h he goal o de ining he secu i y unc ionali-
ies once, and eusing hem o se e al applica ions,
Figu e 2 shows a UML so wa e a chi ec u e wi h
he comple e unc ionali y o all he possible secu i y
conce ns. This includes he In eg i y,Au hen ica ion,
Enc yp ion,Au ho iza ion, and Digi al Signa u e com-
ponen s wi h all kinds o au hen ica ion mechanisms,
enc yp ion algo i hms, and he in eg i y, au ho iza-
ion, and digi al signa u e unc ionali y.3Howe e ,
3To simpli y he case s udy we do no show all he ex-
is ing secu i y p ope ies no all he exis ing algo i hms o
each conce n.
Figu e 1: e-Vo ing so wa e a chi ec u e.
Figu e 2: Secu i y so wa e a chi ec u e.
he e- o ing applica ion only needs a pa icula con-
igu a ion o hese secu i y unc ionali ies based on
he p e ious secu i y equi emen s.
3 OUR PROPOSAL USING CVL
CVL is a domain-independen language o speci y-
ing and esol ing a iabili y. I makes he speci ica-
ion and esolu ion o a iabili y o e any ins ance o
models de ined using a MOF-based me a-model eas-
ie .
Figu e 3 shows ou p oposal using he CVL ap-
p oach. The co e so wa e a chi ec u e o ou base ap-
plica ion and he secu i y so wa e a chi ec u e wi h
all he secu i y unc ionali ies a e he Base Models
and can be de ined in any MOF-de ined language.
The speci ica ion o he a iabili y o he secu i y
conce ns is exp essed in an abs ac le el in he Va i-
abili y Model. The speci ica ion o conc e e a iabili y
in he secu i y model and he secu i y wea ing pa -
e ns o each secu i y conce n a e also de ined in he
a iabili y model. Di e en con igu a ions o he se-
cu i y model a e p o ided in he Resolu ion Models.
These con igu a ions a e selec ions o a se o choices
in he a iabili y model.
CVL p o ides an execu able engine o au oma i-
cally p oduce he Resol ed Models aking as inpu s
he a iabili y model, he esolu ion models and he
base models. In ou p oposal, he esol ed models
a e he so wa e a chi ec u e o he base applica ion
Figu e 3: Ou p oposal using he CVL app oach.
wo en wi h he eques ed secu i y con igu a ion. The
p ocess o de i ing a esol ed model om a base
model gi en a esolu ion model is called ma e ializa-
ion. Apa om esol ing a iabili y, he CVL en-
gine also has he capabili y o delega e i s con ol o a
M2M ans o ma ion engine. This is especially use ul
o de ining domain speci ic ac ions he seman ics o
which a e no de ined by CVL, and i is used in ou
p oposal o implemen he wea ing p ocess be ween
he applica ion a chi ec u e and he secu i y con igu-
a ion a chi ec u e by pe o ming models ans o ma-
ions du ing he execu ion o CVL.
In o de o implemen ou p oposal we use he ol-
lowing concep s o CVL4:
Va iabili y Speci ica ions (VSpecs). They a e pa
o he a iabili y model. They a e ee-based
s uc u es ep esen ing choices,5and can ha e
a ia ion poin s bound o hem. To ma e ialize a
base model wi h a a iabili y model o e i , eso-
lu ions o he VSpecs mus be p o ided. Choices
a e esol ed by deciding hem nega i ely o posi-
i ely.
Va ia ion Poin s. They a e pa o he a iabili y
model and de ine speci ic modi ica ions o be ap-
plied o he base model du ing ma e ializa ion.
They e e o base model elemen s ia base mod-
els handles and a e bound o VSpecs. The appli-
ca ion o he a ia ion poin s depends on he eso-
lu ion o he VSpecs.
Exis ence Va ia ion Poin . I is a kind o a ia ion
poin ha indica es he exis ence o a pa icula
objec , link, o alue in he base model. I s neg-
a i e applica ion in ol es dele ing elemen s om
he base model.
Opaque Va ia ion Poin (OVP). I is a kind o a i-
a ion poin he impac o which on he base model
is use -de ined h ough a model ans o ma ion
language. OVPs allow ex ending and cus omizing
he seman ic o he exis ing CVL a ia ion poin s.
4The comple e desc ip ion o CVL can be ound in
h p://www.omgwiki.o g/ a iabili y/.
5“Fea u es” in mos SPL app oaches.
The AO main concep s ha we use a e:
Join Poin . I is a poin in he model (e.g. a me hod
call in an in e ace) which can be a ec ed by he
c osscu ing beha io .
Ad ice. I is he addi ional beha io ha a ec s he
base p og am a he selec ed join poin s. The e
a e usually h ee kinds o ad ices based on ‘when’
he beha io akes place in e e ence o he join
poin s: be o e,a e , and a ound. A ound ad-
ices allow bypassing he execu ion o he cap-
u ed join poin s.
Poin cu . I is an exp ession ha desc ibes a se o
join poin s.
4 SECURITY WEAVING
In o de o inco po a e a pa icula con igu a ion o
he secu i y unc ionali y in o he base applica ion o
ou case s udy, we implemen he wea ing p ocess us-
ing CVL and, conc e ely, using he OVPs o CVL. Be-
o e ha , we need o cus omize he secu i y so wa e
a chi ec u e om he secu i y equi emen s o ou e-
o ing applica ion. Bo h p ocesses, he selec ion o a
secu i y con igu a ion and he wea ing a e pe o med
in he same s ep using CVL.
Figu e 4 shows an ins ance o ou p oposal us-
ing he CVL app oach wi h ou case s udy and he
secu i y speci ica ions. The a iabili y model o se-
cu i y is speci ied in an abs ac le el using VSpecs
( op o Figu e 4). Secu i y p ope ies a e decomposed
in o choices in he VSpecs, indica ing which secu-
i y conce ns a e op ional and which a e manda o y.
In ou case s udy, o simplici y, secu i y is decom-
posed only in o he choices o In eg i y,Access Con-
ol which in u n con ains he Au hen ica ion and Au-
ho iza ion conce ns, and C yp og aphy ha con ains
he Enc yp ion and Digi al Signa u e conce ns. Each
o hem is also composed by he a ailable me hods
and algo i hms. Fo ins ance, he e a e h ee kinds o
me hods o e i y he in eg i y o he da a: Passwo d
e i ica ion,Da a iden i ie , and Hash e i ica ion. The
las one can be pe o med by using he MD5 o he
SHA-1 algo i hm. The esolu ion o all hese choices
equi e a yes/no decision, and he secu i y con igu a-
ion ( he esolu ion model) is a selec ion o his se o
choices in he VSpecs — i.e. he secu i y conce ns
ha a e decided posi i ely (da kened choices in Fig-
u e 4).
The conc e e a iabili y o secu i y and he wea -
ing pa e ns a e speci ied using a ia ion poin s (mid-
dle o Figu e 4): “objec exis ence” a ia ion poin s
o ealize he a iabili y and OVPs o do he wea -
Figu e 4: Secu i y con igu ing and wea ing using CVL.
ing. The objec exis ence a ia ion poin s a e bound o
choices o he VSpecs and e e o componen s o he
secu i y so wa e a chi ec u e (bo om o Figu e 4).
This kind o a ia ion poin indica es he exis ence o
a pa icula objec (componen ) ha will be included
o emo ed om he secu i y so wa e a chi ec u e
based on he esolu ion p o ided o he associa ed
VSpec. Fo ins ance, he a ia ion poin bound o
he In eg i y conce n in he VSpecs (:Objec Exis ence)
indica es ha i he In eg i y choice is decided posi-
i ely (i.e. is selec ed in he esolu ion model) in a
con igu a ion, he ela ed elemen s ( he In eg i y com-
ponen and i s in e aces wi h hei a achmen s) in
he secu i y so wa e a chi ec u e will exis in he e-
sol ed model and i in eg i y is decided nega i ely
(i.e. is no selec ed in he esolu ion model) hose
ela ed elemen s will be emo ed om he esol ed
model.
The OVPs a e also bound o he VSpecs bu ha e
wo o mo e e e ences in he base models: (1) one
e e ence (sou ce objec s) o he in e ace in he secu-
i y so wa e a chi ec u e he beha io o which we
wan o inco po a e in ou base applica ion — i.e.
he ad ice, and (2) one o mo e e e ences ( a ge
objec s) o he in e aces in he applica ion so wa e
a chi ec u e whe e we wan o inco po a e he secu-
i y conce n — i.e. he join poin s. Fo ins ance,
OVP2 has a e e ence (sou ceObjec ) o he Enc yp-
ionIn in e ace in he secu i y model and wo a ge s
( a ge Objec s): one o enc yp ing ( ha e e ences
o he E o ingIn in e ace in he applica ion model)
and one o dec yp ing ( ha e e ences o he Vo ing-
Da aIn in e ace).
OVPs a e also bound o an OVPType, whe e his
ype explici ly de ines he seman ic o he special sub-
s i u ion — i.e. he ans o ma ion ules o wea e he
secu i y conce ns in o he base applica ion. Each se-
cu i y conce n needs o be wo en wi h he base ap-
plica ion ollowing a di e en ans o ma ion pa e n
based on he aspec ual in o ma ion o he conce n: he
kind o he ad ice ha he conce n implemen s: be-
o e,a e , o a ound; he me hod (ad ice) ha mus
be execu ed by he conce n; and he in e cep ed me h-
ods (join poin s) in he base applica ion. So, using
CVL we need o use se e al a ia ion poin s, wi h
di e en seman ics, o indica e how he elemen s o
he models a e adap ed in o de o gene a e he e-
sol ed model. Du ing a iabili y ma e ializa ion, he
CVL engine will delega e i s con ol o a M2M ans-
o ma ion engine (ATL in ou p oposal) whene e i
encoun e s an OVP. The M2M ans o ma ion engine
execu es he seman ic speci ica ion associa ed wi h
he OVP and esol es he a iabili y acco dingly.
The esol ed model is au oma ically gene a ed
(Figu e 5) and he secu i y con igu a ion is wo en
wi h ou applica ion so wa e a chi ec u e: he com-
ponen s ela ed o he secu i y conce ns a e clea ly
isible in he s a ic pa o he a chi ec u e, and he
ela ionships be ween he secu i y elemen s and he
elemen s o he base applica ion (“c osscu s” depen-
dency ela ionship) explici ly indica e ha he sou ces
o he ela ionships c osscu he a chi ec u al le el,
and he a ge s a e he poin o he applica ion whe e
hey ake place. Howe e , he aspec ual in o ma ion
wi h he in e ac ions be ween he componen s is no
ep esen ed in he so wa e a chi ec u e o Figu e 5.
To comple e he design we complemen he so wa e
a chi ec u e wi h a se o sequence diag ams ha ep-
esen he aspec ual in o ma ion and ha a e also au-
oma ically gene a ed by he wea ing pa e ns (Pin o
e al., 2009). The ollowing sec ion shows he wea -
ing pa e ns, in de ail, o each secu i y conce n.
5 SECURITY WEAVING
PATTERNS
The na u e o each secu i y conce n a oids ha ing o
ha e a unique and homogeneous wea ing pa e n. As
we explained in he p e ious sec ion each conce n
needs di e en aspec ual in o ma ion and he wea -
ing pa e ns (i.e. he ans o ma ion ules) needed o
pe o m he wea ing a e di e en .
The seman ic speci ica ion associa ed wi h each
OVP mus include ans o ma ion ules o: (1) in-
co po a e he secu i y componen s in o he so wa e
a chi ec u e o he base applica ion; (2) c ea e he
“c osscu s” ela ionships be ween he in e ace o he
conce n ( he ad ice) and he in e ace o he applica-
ion whe e he c osscu s ake places ( he join poin );
and (3) gene a e he sequence diag am ha ep esen s
he beha io o he c osscu ing ela ionship.
We de ine a se o ATL ans o ma ions o each
o he secu i y conce ns: au hen ica ion, enc yp ion,
au ho iza ion, in eg i y, and digi al signa u e. Wea -
ing pa e ns o o he secu i y o c osscu ing con-
ce ns may be de ined in a simila way. To pe o m
he wea ing be ween he models, each ATL ans o -
ma ion akes as inpu he wo models ( he applica ion
model and he secu i y model) and gene a es as ou pu
he same applica ion model wi h he app op ia e secu-
i y conce n me ged. The elemen s o he applica ion
model emain unchanged in he ou pu model. So, we
can ocus on he gene a ion o he secu i y elemen s
in he ATL ans o ma ions.
The ans o ma ion ules (wea ing pa e ns) a e
de ined only once and can be eused in each appli-
ca ion. Howe e , he e is speci ic in o ma ion o he
base applica ion ha he so wa e a chi ec mus p o-
ide because i is di e en o each applica ion. Fo
ins ance, he so wa e a chi ec mus de ine he con-
c e e poin cu s (e.g. he me hod signa u e) o he
join poin s in he base applica ion. To simpli y he
case s udy, we only use me hod call/execu ion poin -
cu designa o s. In o de o make he ans o ma ion
ules mo e eusable, we de ine he aspec ual in o ma-
ion as a ibu es (helpe s) in ATL ha mus be illed
in o each applica ion wi h he signa u e o he in e -
cep ed me hod by he c osscu ela ionship.
5.1 Au hen ica ion
The seman ic o he special subs i u ion o he au-
hen ica ion conce n is shown in he Lis ing 1. The
ans o ma ion ule: (1) copies he au hen ica ion se-
cu i y elemen s: he componen (sou ceComp) and
in e ace (sou ceIn ) om he Secu i yModel o he
applica ion model (AppModel in he ule); (2) c e-
a es he “c osscu ” ela ionship be ween he sou ce
(sou ceIn ) and he a ge ( a ge In ) in e aces; and
(3) gene a es he sequence diag am wi h he in e ac-
ions be ween he au hen ica ion and he base applica-
ion elemen s.
The aspec ual in o ma ion is coded in he ans-
o ma ion pa e n and is used o gene a e he in e -
ac ions. Fo ins ance, o gene a e he au hen ica ion
sequence diag am we use a called ule o ATL wi h
he aspec ual in o ma ion: he in e cep ed me hod
o e(Objec ) (p o ided wi h he helpe ope a ion), he
ad ice (‘au hen ica e()’), and he kind o he ad ice
(‘a ound’), apa om he in e aces and componen s
ela ed.
The sequence diag am gene a ed is shown in
Figu e 6. Au hen ica ion is usually pe o med be o e
a me hod call, howe e we use an a ound ad ice in
o de o abo he call o he me hod o e(Objec ) i
he au hen ica ion ails.
Figu e 5: Applica ion wi h secu i y unc ionali y wo en.
Lis ing 1: Seman icSpec1 (SpecialSubs i u ionAu hen)
module au hen ica ion;
c ea e OUT : U ML om AppModel:UML,
Sec u i yMod el : UML ;
ule Au hen ica ion {
om so u ce In : UML ! In e ace in Secu i yModel ,
sou ceC omp : UML ! Compo nen in Secu i yModel ,
a g e In : UML ! In e ace in AppModel ,
( so u ceIn . name = ‘ Au hen ica ionIn ’ and
sou c eCom p . na me = ‘ A u h en ic a ion ’ a nd
a ge In . nam e = hisModule. a ge O bjec )
o sec u i yC om p : UML ! Co mp on en ( ... ) ,
sec u i yIn : UML ! In e ac e (... ) ,
c o ss cu A ss oc : UML ! D ep ende ncy (
clien <- sou ceIn ,
supplie <- a ge In , ...)
do {c osscu Assoc.applyS e eo ype(
hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ;
hisModule. C e a eAu hI n e ac i on ( a ge In ,
sou ceIn , sou ceComp , ‘a ound ’,
hisModule. o pe a i on , ‘ a u h en i ca e () ’) ;}
}
5.2 Enc yp ion
The seman ic o he special subs i u ion o he en-
c yp ion conce n (Lis ing 2) is di e en since i
uses wo di e en ad ices (‘enc yp (Objec )’ and ‘de-
c yp (Objec )’) in wo di e en poin s o he appli-
ca ion. The o es a e enc yp ed in he o e(Objec )
me hod o he EVo ingIn in e ace (p o ided by
he ope Enc yp helpe ), and a e dec yp ed in he
ge Vo e() me hod o he Vo ingDa aIn in e ace (p o-
Figu e 6: Au hen ica ion sequence diag am.
ided by he ope Dec yp helpe ). The ans o ma ion
ule au oma ically gene a es wo di e en sequence
diag ams wi h ha in o ma ion: one o enc yp ing
(Figu e 7) and one o dec yp ing (Figu e 8).
Lis ing 2: Seman icSpec2 (SpecialSubs i u ionEnc yp )
module enc yp ion ;
c ea e OUT : U ML om AppModel:UML,
Sec u i yMod el : UML ;
ule Enc yp ion {
om so u ce In : UML ! In e ace in Secu i yModel ,
sou c eC omp : UML ! Compo nen in Secu i yModel ,
a ge E nc y pIn : UM L ! In e ace in AppModel ,
a ge D ec y pIn : UM L ! In e ace in AppModel ,
( so u ceIn . name = ‘ Enc yp ionIn ’ and
s ou c eC om p . n ame = ‘ E nc yp io n ’ an d
a ge D ec ypI n . name = hisModule.
a ge Obje c 1 and
a ge E nc y p In . name = hisModule.
a ge Obje c 2 )
o sec u i yC om p : UML ! Co mp on en ( ... ) ,
sec u i yIn : UML ! In e ac e (... ) ,
c o ss cu A ss oc1 : UML ! D epen denc y (
clien <- sou ceIn ,
supplie <- a ge Enc yp In , ...),
c o ss cu A ss oc2 : UML ! D epen denc y (
clien <- sou ceIn ,
supplie <- a ge Dec yp In , ...)
do {c osscu Assoc1.applyS e eo ype(
hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ;
c osscu Assoc2.applyS e eo ype(
hisModule. g e S e e o yp e ( ‘ c os sc u s ’) ) ;
hisModule. C ea eEn c yp In e ac ion (
a ge Enc yp In , sou ceIn , sou ceComp ,
‘a ound ’, hisModule.ope Enc yp ,
‘ enc yp ( Objec ) ’);
hisModule. C ea eEn c yp In e ac ion (
a ge Dec yp In , sou ceIn ,
sou ceComp , ‘ a ound ’,
hisModule.ope Dec yp ,
‘ dec yp ( Objec ) ’) ;}
}
Figu e 7: Enc yp ion sequence diag am o enc yp ing.
Figu e 8: Enc yp ion sequence diag am o dec yp ing.
5.3 Digi al Signa u e
The wea ing pa e n o he digi al signa u e conce n
is e y simila o he enc yp ion pa e n, bu we only
need he ‘sign(Objec )’ ad ice. We use an a e ad ice
o sign he o es in he se e side a e sending hem
in o de o p e en de ice clien s wi h lowe esou ces
om cas ing hei o es. The sequence diag am o
Figu e 9 shows ha he ad ice ‘sign(Objec )’ is pe -
o med a e he execu ion o he me hod o e(Objec ).
Figu e 9: Digi al signa u e sequence diag am.
5.4 In eg i y
The in eg i y conce n gua an ees he o es belong o
an eligible o e . The wea ing pa e n is also simila
o he enc yp ion pa e n. We use an a ound ad ice
o e he me hod s o eVo e(Objec ) o he Vo ingS o -
eIn in e ace wi h he pu pose o e i ying he au-
hen ici y o he o e and ejec ing i i he o e be-
longs o an in alid o e (see he sequence diag am o
Figu e 10).
Figu e 10: In eg i y sequence diag am.
5.5 Au ho iza ion
The au ho iza ion wea ing pa e n is simila o he au-
hen ica ion case, and in mos secu i y app oaches he
au ho iza ion conce n is based on di e en au hen i-
ca ion mechanisms. In ou e- o ing applica ion we
use a be o e ad ice in o de o g an o deny pe mis-
sions o access p i ileged da a o he elec ion p ocess.
The sequence diag am (Figu e 11) shows ha he au-
ho iza ion logic e i ies he pe missions o he ad-
minis a o be o e calling any me hod o he Vo ingM-
ngIn in e ace.
6 RELATED WORK
Secu i y is usually achie ed in se e al ways, bu mos
o he app oaches p esen he secu i y as a se o non-
Figu e 11: Au ho iza ion sequence diag am.
unc ional p ope ies, ins ead o ocusing on he unc-
ional pa o he secu i y conce ns as we do. Fo in-
s ance, in (Geo g e al., 2002), he au ho s analyze he
impac o secu i y p ope ies on o he unc ional con-
ce ns o he base applica ion using an AO app oach.
Model D i en Enginee ing (MDE) has also been
used in he ield o SPLs (Sij ema, 2010). Sij ema
p oposes a s a egy o le ATL handle he a iabili y
by ex ending he conc e e syn ax o ATL wi h he con-
cep o a iabili y ules. Va iabili y ules a e used in
he con ex o a ans o ma ion sequence which suc-
cessi ely e ines models. Howe e , hey i s model
he a iabili y sepa a ely in a ea u e diag am and
ha e o make he co espondence be ween he ea u e
selec ions and he ealiza ion o he a e ac s. In com-
pa ison wi h ou p oposal, using CVL we model he
a iabili y and bind he ea u es di ec ly o he ele-
men s in he so wa e a chi ec u e. We use he basic
ATL wi hou he need o ex end i , bu ou p oposal
can also be used wi h o he ans o ma ion languages
such as QVT o ETL (Epsilon T ans o ma ion Lan-
guage) (Kolo os e al., 2008).
Recen ly, CVL has been applied in mul iple ap-
p oaches. Fo ins ance, CVL is used o manage
he a iabili y in he con ex o so wa e p ocesses
(Rouill´
e e al., 2012), business p ocess (Ayo a e al.,
2012), o e en o syn hesizing an SPL using model
compa ison (Zhang e al., 2011). In (Combemale
e al., 2012) CVL is used o speci y and esol e he
a iabili y o a so wa e design, and he Reusable
Aspec Model (RAM) echnique is used o speci y
and compose he de ailed s uc u al and beha io al
design models co esponding o he chosen a ian s.
Ou app oach, in con as , ocuses on he a chi ec u al
le el in he de elopmen p ocess, and we pe o m he
wea ing p ocess wi h he CVL engine, ins ead o us-
ing an ex e nal RAM wea e .
7 CONCLUSIONS AND FUTURE
WORK
We ha e de ined a se o secu i y wea ing pa e ns
h ough model ans o ma ions in ATL ha allows
he au oma ic inco po a ion o a cus omized secu i y
model in o he base applica ion model by using CVL
and AOSD. CVL makes ou p oposal sui able o use
wi h any MOF based model. We ha e implemen ed
ou p oposal and used i wi h se e al case s udies such
as he e- o ing applica ion p esen ed in his pape o
in a ehicle- o- ehicle and ehicle- o-in as uc u e
applica ion ha is ano he o he demons a o s o he
INTER-TRUST p ojec . In all cases, we ha e used
UML as he modeling language o he so wa e a chi-
ec u es and we conclude ha ou p oposal imp o es
he modula i y and eusabili y o bo h so wa e a chi-
ec u es, he co e a chi ec u e o he applica ion and
he secu i y so wa e a chi ec u e.
As pa o ou u u e wo k, we plan o make he
ans o ma ion ules mo e eusable by using a hi d
binding model in he wea ing pa e ns (Du ´
an e al.,
2013). The binding model allows de ining he aspec-
ual in o ma ion (e.g. poin cu de ini ions, ad ices)
as ex e nal pa ame e s o use hem in he ans o ma-
ion ules independen ly om he inpu models. We
also plan o ake in o accoun he exis ing dependen-
cies be ween he secu i y conce ns (e.g. au hen ica-
ion is usually needed by he au ho iza ion conce n),
and how hese dependencies a ec he wea ing pa -
e ns and he sequence diag ams when wo o mo e
conce ns a e applied in he same poin o he appli-
ca ion. Mo eo e , we plan o de ine wea ing pa e ns
o o he c osscu ing conce ns such as usabili y, pe -
sis ence, con ex -awa eness, e c.
ACKNOWLEDGEMENTS
Wo k suppo ed by he Eu opean P ojec INTER-
TRUST 317731 and he Spanish P ojec s TIN2012-
34840 and FamiWa e P09-TIC-5231.
REFERENCES
Ayo a, C., To es, V., Pelechano, V., and Al ´
e ez, G. H.
(2012). Applying CVL o business p ocess a iabil-
i y managemen . In P oceedings o he VARiabili y
o You Wo kshop: Va iabili y Modeling Made Use-
ul o E e yone, VARY ’12, pages 26–31, New Yo k,
NY, USA. ACM.
Combemale, B., Ba ais, O., Alam, O., and Kienzle, J.
(2012). Using CVL o Ope a ionalize P oduc Line