8th European Symposium on Research in Computer Security (ESORICS 2003)

Bridging Model-Based and Language-Based Security

Rogardt Heldal, Fredrik Hultin

Abstract : We present a way to support the development of software applications that takes into account confidentiality issues, and how the developed code can be automatically verified. We use the Unified Modelling Language (UML) together with annotations to permit confidentiality to be considered during the whole development process from requirements to code. We have provided support for software development using UML diagrams so that the code produced can be be validated by a language-based checker, in our case Jif (Java information flow). We demonstrate that the combination of model-based and language-based security is compelling.

