Requirements engineering for trust management: Model, methodology, and reasoning

被引:0
|
作者
Giorgini P. [1 ]
Massacci F. [1 ]
Mylopoulos J. [1 ]
Zannone N. [1 ]
机构
[1] Department of Information and Communication Technology, University of Trento, Trento
关键词
Agent-oriented software; Privilege management; Requirements Engineering; Security Engineering; Trust models for business and organizations; Verification and validation of software;
D O I
10.1007/s10207-006-0005-7
中图分类号
学科分类号
摘要
A number of recent proposals aim to incorporate security engineering into mainstream software engineering. Yet, capturing trust and security requirements at an organizational level, as opposed to an IT system level, and mapping these into security and trust management policies is still an open problem. This paper proposes a set of concepts founded on the notions of ownership, permission, and trust and intended for requirements modeling. It also extends Tropos, an agent-oriented software engineering methodology, to support security requirements engineering. These concepts are formalized and are shown to support the automatic verification of security and trust requirements using Datalog. To make the discussion more concrete, we illustrate the proposal with a Health Care case study. © Springer-Verlag 2006.
引用
收藏
页码:257 / 274
页数:17
相关论文
共 50 条
  • [31] Requirements management within a full model-based engineering approach
    Bernard, Yves
    SYSTEMS ENGINEERING, 2012, 15 (02) : 119 - 139
  • [32] A conceptual model for requirements engineering and management for change-intensive software
    Botaschanjan, J
    Fleischmann, A
    Pister, M
    Proceedings of the IASTED International Conference on Software Engineering, 2004, : 36 - 41
  • [33] Review of Knowledge Engineering Requirements for Semantic Reasoning in Autonomic Networks
    Strassner, John
    Foghlu, Micheal O.
    Donnelly, Willie
    Serrat, Joan
    Agoulmine, Nazim
    CHALLENGES FOR NEXT GENERATION NETWORK OPERATIONS AND SERVICE MANAGEMENT, PROCEEDINGS, 2008, 5297 : 146 - +
  • [34] A Reference Model for requirements engineering
    Hall, JG
    Rapanotti, L
    11TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE, PROCEEDINGS, 2003, : 181 - 187
  • [35] STORE: Security Threat Oriented Requirements Engineering Methodology
    Ansari, Md Tarique Jamal
    Pandey, Dhirendra
    Alenezi, Mamdouh
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (02) : 191 - 203
  • [36] An Intelligent Methodology to Enhance Requirements Engineering in Multidisciplinary Projects
    Salmani, Ali
    Imani, Alireza
    Bahrehvar, Majid
    Duffett-Leger, Linda
    Moshirpour, Mohammad
    2022 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2022, : 452 - 457
  • [37] Advanced methodology for requirements engineering technique solution (AMRETS)
    Siahaan, D. (daniel@if.its.ac.id), 1600, Advanced Institute of Convergence Information Technology (04):
  • [38] Model driven requirements engineering
    GEBIT Solutions GmbH, Germany
    Inform.-Spektrum, 2006, 6 (460-464):
  • [39] A requirements engineering reference model
    Broy, Manfred
    Geisberger, Eva
    Kazmeier, Jürgen
    Rudorfer, Arnold
    Beetz, Klaus
    Informatik-Spektrum, 2007, 30 (03) : 127 - 142
  • [40] Requirements engineering, soft systems methodology and workforce empowerment
    Probert S.K.
    Requirements Engineering, 1999, 4 (2) : 77 - 84