Secure Design and Development – PixelForge Nexus (UITS)
This assessment for Coventry University’s Secure Design and Development module requires students to design and develop a functional secure online system with the aid of a Large Language Model (LLM). The assignment is based on a practical scenario involving Creative SkillZ LLC and its proposed “PixelForge Nexus” system. The submission combines a functional prototype, an individual 2,000-word report, source code hosted in the Coventry University GitHub environment, and a video report demonstrating the completed prototype. The PixelForge Nexus prototype is intended to provide secure project management and basic asset and resource management for a game-development environment. Core functionality includes adding and removing projects, viewing active projects, assigning developers to projects, allowing developers to view their assigned projects, uploading project documents, and allowing authorised users to access documents associated with their projects. The system must implement privilege separation between Admin, Project Lead and Developer roles. Security is a central requirement of the assignment. Administrators are responsible for managing projects and user accounts, Project Leads can assign developers and upload project documents, while Developers can view assigned projects and associated documents. The system must include a robust login mechanism with secure password hashing and storage, with Multi-Factor Authentication recommended as an additional security measure. Proposed pages include Sign In/Register, a role-based User Dashboard, Account Settings and a Project Details page. The practical assessment evaluates four major areas: System Design, Security Testing and Analysis, System Development, and Formal Methods. System design requires consideration of secure design principles and their application to the development lifecycle. Security testing requires critical evaluation of security techniques, identification of issues and proposed mitigation measures. System development requires a functional prototype that follows the proposed design and considers legal and ethical requirements. Formal methods require a behavioural model and appropriate verification techniques to establish whether the system meets its specification. The individual report must document the methods and techniques used to develop the prototype and discuss the stages of the development lifecycle, including specification, design and development. It must also explain the deployment and testing approach, limitations of the prototype, possible improvements, security techniques and the formal model used. The submission must include links to the Coventry University GitHub repository and Microsoft OneDrive video, while the required appendix contains the LLM prompt history and other resources used with APA-style referencing.
Read Model Answer →