DocumentCode
2358643
Title
Security Policy Enforcement in BPEL-Defined Collaborative Business Processes
Author
Fischer, Klaus-Peter ; Bleimann, Udo ; Fuhrmann, Woldemar ; Furnell, Steven M.
Author_Institution
Digamma Commun. Consulting GmbH, Darmstadt
fYear
2007
fDate
17-20 April 2007
Firstpage
685
Lastpage
694
Abstract
This paper presents an approach to security policy enforcement with collaborative business processes defined using BPEL and deployed across enterprise domain boundaries for execution. The assessment of compliance with security policies at the location where a BPEL script is to be executed is facilitated by re-formulating the security policies with respect to the potential of violation inherent in BPEL The results of an analysis of the security-relevant semantics of BPEL-defined business processes conducted for this purpose indicate the paramount role of information flow analysis in business processes. Based on these results, the paper proposes an XML-based schema for specifying security policies for cross-organisational business processes that allows for automatic checking of BPEL scripts for compliance to these security policies. The paper also introduces a prototype implementation of an automatic compliance check that approves the feasibility of the method for practical application in security policy enforcement.
Keywords
XML; business data processing; security of data; BPEL-defined collaborative business processes; XML-based schema; automatic compliance check; cross-organisational business processes; enterprise domain boundaries; security policy enforcement; security-relevant semantics; Business communication; Collaboration; Control systems; Informatics; Information analysis; Information security; Manufacturing processes; Process control; Prototypes; Web services; Business Process Execution Language (BPEL); Collaborative Business Processes; Information Flow Analysis; Security Policy Enforcement; Semantic Analysis; Service Oriented Computing (SOC); Web Services;
fLanguage
English
Publisher
ieee
Conference_Titel
Data Engineering Workshop, 2007 IEEE 23rd International Conference on
Conference_Location
Istanbul
Print_ISBN
978-1-4244-0832-0
Electronic_ISBN
978-1-4244-0832-0
Type
conf
DOI
10.1109/ICDEW.2007.4401056
Filename
4401056
Link To Document