Sciweavers

DEXAW
2009
IEEE

Towards a Generic Process for Security Pattern Integration

13 years 8 months ago
Towards a Generic Process for Security Pattern Integration
Abstract--Interdependencies between different security patterns can influence the properties of a particular pattern when applied in conjunction with other patterns. The resulting properties will often be weaker due to the possibility of new attacks. In this paper we introduce a mechanism that leads towards a generic process for pattern integration. As an example, we use the interesting case in which the proper integration of two patterns provides stronger security properties than the simple unification of the two properties. Formally, this increase in security is achieved by linking parameters of refined versions of the individual properties. The example shows the combination of two different authenticity properties (authenticity of a device based on trusted platform module functionality and authenticity of a user by using SSL). Remarkably, previously proposed combinations of solutions do not satisfy the desired integrated security properties. This indicates that pattern integration r...
Andreas Fuchs, Sigrid Gürgens, Carsten Rudolp
Added 16 Aug 2010
Updated 16 Aug 2010
Type Conference
Year 2009
Where DEXAW
Authors Andreas Fuchs, Sigrid Gürgens, Carsten Rudolph
Comments (0)