Eddy Truyen , Katholieke Universiteit Leuven
Tine Verhanneman , Katholieke Universiteit Leuven
Bart De Win , Katholieke Universiteit Leuven
Frank Piessens , Katholieke Universiteit Leuven
Wouter Joosen , Katholieke Universiteit Leuven
Access control services integrated in current middleware technologies fall short whenever application-specific access control policies must be enforced. As a consequence, developers embed access control logic in the code, resulting in an unmaintainable access control enforcement. The authors use aspect-oriented software development techniques to better separate application logic and access control by describing the design and implementation of a modular access control service. They have implemented a prototype in CaesarJ, a research aspect-oriented programming language.
design tools, security, access control, aspect-oriented programming
