• DocumentCode
    1496043
  • Title

    The Integration of Corporate Security Strategies in Collaborative Business Processes

  • Author

    Badr, Youakim ; Biennier, Frédérique ; Tata, Samir

  • Author_Institution
    Dept. Inf., INSA de Lyon, Villeurbanne, France
  • Volume
    4
  • Issue
    3
  • fYear
    2011
  • Firstpage
    243
  • Lastpage
    254
  • Abstract
    In response to increasing economical constraints, enterprise organization has evolved toward new structures such as networked enterprise, supply chains, virtual enterprise, or collaborative business organizations. This structural organization requires the interoperability of business processes (BPs)and information systems. Dealing with interoperability often leads to the deployment of Service-Oriented Architecture (SOA) based on Enterprise Service Bus (ESB) to design agile collaborative BPs and publish and compose new services. In order to protect each partner´s own interests, security strategies must be developed and integrated in the service environment. Unfortunately, traditional security approaches deal with security concerns from a technical perspective (i.e., data transmission or authentication, etc.) and do not support end-to-end security in a distributed environment of business services and collaborative processes. In this paper, we attempt to improve end-to-end security by annotating service descriptions with security objectives used to generate convenient quality of protection (QoP) agreements between partners. Conversely, agreements are processed by a dedicated matching module with respect to security requirements and preferences to select business services, and then, compose their appropriate technical security services.
  • Keywords
    groupware; information systems; open systems; security of data; service-oriented architecture; virtual enterprises; agile collaborative BP; business processes interoperability; collaborative business processes; corporate security strategies; economical constraints; enterprise organization; enterprise service bus; information systems; networked enterprise; quality of protection agreements; service oriented architecture; supply chains; virtual enterprise; Collaboration; Communities; Context; Information systems; Organizations; Security; Computer security; data processing; distributed information system.;
  • fLanguage
    English
  • Journal_Title
    Services Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1939-1374
  • Type

    jour

  • DOI
    10.1109/TSC.2010.18
  • Filename
    5467020