DocumentCode
1831776
Title
Responsibility-driven Design and Development of Process-aware Security Policies
Author
Leitner, Maria ; Rinderle-Ma, Stefanie ; Mangler, Juergen
Author_Institution
Univ. of Vienna, Vienna, Austria
fYear
2011
fDate
22-26 Aug. 2011
Firstpage
334
Lastpage
341
Abstract
Process-Aware Information Systems (PAIS) enable the automated support of business processes that are executed by a combination of human actors and systems. As processes typically require access to sensitive data, security policies are of high importance. Typically security policies in PAIS range from access rules and authorization constraints to context policies (location, time) and are scattered over the multitude of heterogeneous PAIS components, i.e. process models, repositories, organizational structures, etc. Currently, different approaches for modeling and enforcing security policies exist that assume a set of explicitly defined security policies. Because of aforementioned heterogeneity, these approaches are suboptimal for PAIS. In order to improve upon existing approaches we present a security policy data model and design methodology, based on the concept of responsibilities, permissions and constraints. The goal is to not only unify diverse security policies in different PAIS subsystems, but also to make security policies independent of these subsystems to restrain complexity from process modeling and evolution, and to allow for comprehensive security policy development and maintenance.
Keywords
authorisation; business data processing; access rules; authorization constraints; business processes; context policies; process-aware information systems; process-aware security policies; responsibility-driven design; Authorization; Business; Context; Data models; Monitoring; Process control; Process Aware Information Systems; Security Policy Design; Security Policy Development;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location
Vienna
Print_ISBN
978-1-4577-0979-1
Electronic_ISBN
978-0-7695-4485-4
Type
conf
DOI
10.1109/ARES.2011.56
Filename
6045959
Link To Document