DocumentCode :
2110421
Title :
Verification of Dynamic Separation of Duty Policy for Role-based Business Processes
Author :
Thipse, Aashay ; Hewett, Rattikorn
Author_Institution :
Dept. of Comput. Sci., Texas Tech Univ., Lubbock, TX
fYear :
2008
fDate :
17-20 April 2008
Firstpage :
1
Lastpage :
6
Abstract :
Separation of duty (SoD) is a widely used security principle to help prevent frauds in a business process. Though SoD has been studied by many researchers, most of them are concerned with specifications of various types of SoD constraints for policy enforcement. For large organizations that employ SoD policies, the ability to automatically verify if a given user-role assignment complies with SoD policies is of the great value for security management. This paper proposes an algorithm for constraint checking of simple dynamic SoD. Unlike most previous work that enforces SoD policy at run time (when roles are activated), our approach examines policy enforcement build-time (prior to run rime, i.e. when roles are assigned to users but not activated).
Keywords :
business data processing; fraud; constraint checking algorithm; dynamic separation verification; policy enforcement; role-based business processes; security management; separation of duty; Access control; Automatic control; Automation; Computer science; Computer security; Information security; Qualifications;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Region 5 Conference, 2008 IEEE
Conference_Location :
Kansas City, MO
Print_ISBN :
978-1-4244-2076-6
Electronic_ISBN :
978-1-4244-2077-3
Type :
conf
DOI :
10.1109/TPSD.2008.4562752
Filename :
4562752
Link To Document :
بازگشت