• Skip to content (access key 1)
  • Skip to search (access key 7)
FWF — Austrian Science Fund
  • Go to overview page Discover

    • Research Radar
      • Research Radar Archives 1974–1994
    • Discoveries
      • Emmanuelle Charpentier
      • Adrian Constantin
      • Monika Henzinger
      • Ferenc Krausz
      • Wolfgang Lutz
      • Walter Pohl
      • Christa Schleper
      • Elly Tanaka
      • Anton Zeilinger
    • Impact Stories
      • Verena Gassner
      • Wolfgang Lechner
      • Birgit Mitter
      • Oliver Spadiut
      • Georg Winter
    • scilog Magazine
    • Austrian Science Awards
      • FWF Wittgenstein Awards
      • FWF ASTRA Awards
      • FWF START Awards
      • Award Ceremony
    • excellent=austria
      • Clusters of Excellence
      • Emerging Fields
    • In the Spotlight
      • 40 Years of Erwin Schrödinger Fellowships
      • Quantum Austria
    • Dialogs and Talks
      • think.beyond Summit
    • Knowledge Transfer Events
    • E-Book Library
  • Go to overview page Funding

    • Portfolio
      • excellent=austria
        • Clusters of Excellence
        • Emerging Fields
      • Projects
        • Principal Investigator Projects
        • Principal Investigator Projects International
        • Clinical Research
        • 1000 Ideas
        • Arts-Based Research
        • FWF Wittgenstein Award
      • Careers
        • ESPRIT
        • FWF ASTRA Awards
        • Erwin Schrödinger
        • doc.funds
        • doc.funds.connect
      • Collaborations
        • Specialized Research Groups
        • Special Research Areas
        • Research Groups
        • International – Multilateral Initiatives
        • #ConnectingMinds
      • Communication
        • Top Citizen Science
        • Science Communication
        • Book Publications
        • Digital Publications
        • Open-Access Block Grant
      • Subject-Specific Funding
        • AI Mission Austria
        • Belmont Forum
        • ERA-NET HERA
        • ERA-NET NORFACE
        • ERA-NET QuantERA
        • Alternative Methods to Animal Testing
        • European Partnership BE READY
        • European Partnership Biodiversa+
        • European Partnership BrainHealth
        • European Partnership ERA4Health
        • European Partnership ERDERA
        • European Partnership EUPAHW
        • European Partnership FutureFoodS
        • European Partnership OHAMR
        • European Partnership PerMed
        • European Partnership Water4All
        • Gottfried and Vera Weiss Award
        • LUKE – Ukraine
        • netidee SCIENCE
        • Herzfelder Foundation Projects
        • Quantum Austria
        • Rückenwind Funding Bonus
        • WE&ME Award
        • Zero Emissions Award
      • International Collaborations
        • Belgium/Flanders
        • Germany
        • France
        • Italy/South Tyrol
        • Japan
        • Korea
        • Luxembourg
        • Poland
        • Switzerland
        • Slovenia
        • Taiwan
        • Tyrol–South Tyrol–Trentino
        • Czech Republic
        • Hungary
    • Step by Step
      • Find Funding
      • Submitting Your Application
      • International Peer Review
      • Funding Decisions
      • Carrying out Your Project
      • Closing Your Project
      • Further Information
        • Integrity and Ethics
        • Inclusion
        • Applying from Abroad
        • Personnel Costs
        • PROFI
        • Final Project Reports
        • Final Project Report Survey
    • FAQ
      • Project Phase PROFI
      • Project Phase Ad Personam
      • Expiring Programs
        • Elise Richter and Elise Richter PEEK
        • FWF START Awards
  • Go to overview page About Us

    • Mission Statement
    • FWF Video
    • Values
    • Facts and Figures
    • Annual Report
    • What We Do
      • Research Funding
        • Matching Funds Initiative
      • International Collaborations
      • Studies and Publications
      • Equal Opportunities and Diversity
        • Objectives and Principles
        • Measures
        • Creating Awareness of Bias in the Review Process
        • Terms and Definitions
        • Your Career in Cutting-Edge Research
      • Open Science
        • Open-Access Policy
          • Open-Access Policy for Peer-Reviewed Publications
          • Open-Access Policy for Peer-Reviewed Book Publications
          • Open-Access Policy for Research Data
        • Research Data Management
        • Citizen Science
        • Open Science Infrastructures
        • Open Science Funding
      • Evaluations and Quality Assurance
      • Academic Integrity
      • Science Communication
      • Philanthropy
      • Sustainability
    • History
    • Legal Basis
    • Organization
      • Executive Bodies
        • Executive Board
        • Supervisory Board
        • Assembly of Delegates
        • Scientific Board
        • Juries
      • FWF Office
    • Jobs at FWF
  • Go to overview page News

    • News
    • Press
      • Logos
    • Calendar
      • Post an Event
      • FWF Informational Events
    • Job Openings
      • Enter Job Opening
    • Newsletter
  • Discovering
    what
    matters.

    FWF-Newsletter Press-Newsletter Calendar-Newsletter Job-Newsletter scilog-Newsletter

    SOCIAL MEDIA

    • LinkedIn, external URL, opens in a new window
    • , external URL, opens in a new window
    • Facebook, external URL, opens in a new window
    • Instagram, external URL, opens in a new window
    • YouTube, external URL, opens in a new window

    SCILOG

    • Scilog — The science magazine of the Austrian Science Fund (FWF)
  • elane login, external URL, opens in a new window
  • Scilog external URL, opens in a new window
  • de Wechsle zu Deutsch

  

A Generic Platform for Model Driven Business Security

A Generic Platform for Model Driven Business Security

Ruth Breu (ORCID: 0000-0001-7093-4341)
  • Grant DOI 10.55776/P20388
  • Funding program Principal Investigator Projects
  • Status ended
  • Start July 1, 2008
  • End May 31, 2012
  • Funding amount € 275,930
  • Project website

Disciplines

Computer Sciences (100%)

Keywords

    Software Engineering, IT-Security, Model Driven, Software Development

Abstract Final report

Due to the distributed nature of software in the Internet age, almost all enterprise business applications are security sensitive. Developing software systems ensuring the required level of security is therefore one of the big challenges in IT in the next decade and a major key for improvement is Software Engineering. Raising the state-of-the-art from Software Engineering to Security Engineering developers have to be supported by concepts, methods and tools for the systematic and cost-effective development of secure solutions. This comprises the specification of security requirements as a basis of a seamless lifecycle of security-critical systems, systematic business driven security risk analysis as a basis for selecting cost-effective solutions and the development of high- level security services as building blocks of component-based software construction. SECTISSIMO focuses on foundational aspects of the development and use of security services following a model driven approach. SECTISSIMO will provide a generic extensible platform for defining and composing security services. Examples of such security services range from confidential document exchange to non-repudiation and rights delegation. Main aspects within the focus of SECTISSIMO are a rigorous layered architecture separating business level aspects, platform independent security solutions and technology dependent controls. Moreover, we will develop a foundational approach for the composition and interference of security services.

The goal of SECTISSIMO has been to provide tool-based concepts for the business oriented enforcement of security requirements in dynamic distributed environments. The field of MDS (Model Driven Security) has been significantly enhanced by integrating pattern refinement concepts into the traditional transformation functions. Furthermore, an enforcement model based on the concept of Security as a service has been investigated. SECTISSIMO builds upon the concepts of our previous framework SECTET a framework for Model driven Security. SECTET supports business partners during the development and distributed management of decentralized, security critical collaborations across domain boundaries. SECTET primarily aimed at the correct technical implementation of business level security requirements: the transformation functions directly generated code artifacts configuring the partners target infrastructures based on the abstract models which defined the functional and security requirements. SECTISSIMOs three-layered approach overcomes the central limitations of the initial two-layered approach and realized the following key innovations: 1. SECTISSIMOs Model Transformation Concept supports a guided refinement process allowing the security engineer to specify platform independent services which are gradually enriched with architectural, platform specific and technical detail. The security engineer can choose from various architectural patterns (e.g., brokered or direct authentication, single-sign-on etc.) for every abstract security requirement. The transformation component supports the refinement process in a generic and flexible way such that a change of pattern or the enhancement of the framework by new patterns have local effects only. 2. SECTISSIMOs Code Generation Component implements an adaptor-style concept facilitating the enrichment of the chosen platform independent patterns with implementation specific detail and the generation of code artifacts complying with various (XML-) standards. The specific format and syntax of code artifacts are configured through meta-models that are loaded into the framework. 3. SECTISSIMOs Security as a Service Reference Architecture (SeAA) transposes the model of Software as a Service to the domain of security architectures. SeAAS resolves a variety of the conceptual issues linked with the current practice to implement security functionality exclusively at the end-point. We could demonstrate both the applicability of SeAAS concerning performance aspects and for realizing complex security requirements of decentralized processes involving two or more domains.

Research institution(s)
  • Universität Innsbruck - 100%

Discovering
what
matters.

Newsletter

FWF-Newsletter Press-Newsletter Calendar-Newsletter Job-Newsletter scilog-Newsletter

Contact

Austrian Science Fund (FWF)
Georg-Coch-Platz 2
(Entrance Wiesingerstraße 4)
1010 Vienna

office(at)fwf.ac.at
+43 1 505 67 40

General information

  • Job Openings
  • Jobs at FWF
  • Press
  • Philanthropy
  • scilog
  • FWF Office
  • Social Media Directory
  • LinkedIn, external URL, opens in a new window
  • , external URL, opens in a new window
  • Facebook, external URL, opens in a new window
  • Instagram, external URL, opens in a new window
  • YouTube, external URL, opens in a new window
  • Cookies
  • Whistleblowing/Complaints Management
  • Accessibility Statement
  • Data Protection
  • Acknowledgements
  • IFG-Form
  • Social Media Directory
  • © Österreichischer Wissenschaftsfonds FWF
© Österreichischer Wissenschaftsfonds FWF