Title :
Security Requirements Specification in Service-Oriented Business Process Management
Author :
Menzel, Michael ; Thomas, Ivonne ; Meinel, Christoph
Author_Institution :
Hasso-Plattner-Inst., Potsdam
Abstract :
Service-oriented Architectures deliver a flexible infrastructure to allow independently developed software components to communicate in a seamless manner. In the scope of organisational workflows, SOA provides a suitable foundation to execute business processes as an orchestration of multiple independent services. Along with the increased connectivity, the corresponding security risks rise exponentially. However, security requirements are usually defined on a technical level, rather than on an organisational level that would provide a comprehensive view on the participants, the assets and their relationships regarding security. In this paper, we propose an approach to describe security requirements at the business process layer and their translation to concrete security configuration for service-based systems. We introduce security elements for business process modelling which allow to evaluate the trustworthiness of participants based on a rating of enterprise assets and to express security intentions such as confidentiality or integrity on an abstract level. Our aim is to facilitate the generation of security configurations based on the modelled requirements. For this purpose, we foster a model-driven approach: Information at the modelling layer is gathered and translated to a domain-independent security model. Concrete protocols and security mechanisms are resolved based on a security pattern system that is introduced in the course of this paper.
Keywords :
Web services; business data processing; formal specification; object-oriented programming; protocols; risk analysis; security of data; software architecture; workflow management software; business process management; business process modelling; concrete protocol; domain-independent security model; model-driven approach; organisational workflow; security pattern system; security requirement specification; security risk; service-oriented architecture; software component; Authorization; Availability; Business communication; Computer architecture; Concrete; Conference management; Information security; Protocols; Service oriented architecture; Software development management; Business Process Management; SOA Security; Security Requirement Specification; Web Service Security;
Conference_Titel :
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-3572-2
Electronic_ISBN :
978-0-7695-3564-7
DOI :
10.1109/ARES.2009.90