• DocumentCode
    2358643
  • Title

    Security Policy Enforcement in BPEL-Defined Collaborative Business Processes

  • Author

    Fischer, Klaus-Peter ; Bleimann, Udo ; Fuhrmann, Woldemar ; Furnell, Steven M.

  • Author_Institution
    Digamma Commun. Consulting GmbH, Darmstadt
  • fYear
    2007
  • fDate
    17-20 April 2007
  • Firstpage
    685
  • Lastpage
    694
  • Abstract
    This paper presents an approach to security policy enforcement with collaborative business processes defined using BPEL and deployed across enterprise domain boundaries for execution. The assessment of compliance with security policies at the location where a BPEL script is to be executed is facilitated by re-formulating the security policies with respect to the potential of violation inherent in BPEL The results of an analysis of the security-relevant semantics of BPEL-defined business processes conducted for this purpose indicate the paramount role of information flow analysis in business processes. Based on these results, the paper proposes an XML-based schema for specifying security policies for cross-organisational business processes that allows for automatic checking of BPEL scripts for compliance to these security policies. The paper also introduces a prototype implementation of an automatic compliance check that approves the feasibility of the method for practical application in security policy enforcement.
  • Keywords
    XML; business data processing; security of data; BPEL-defined collaborative business processes; XML-based schema; automatic compliance check; cross-organisational business processes; enterprise domain boundaries; security policy enforcement; security-relevant semantics; Business communication; Collaboration; Control systems; Informatics; Information analysis; Information security; Manufacturing processes; Process control; Prototypes; Web services; Business Process Execution Language (BPEL); Collaborative Business Processes; Information Flow Analysis; Security Policy Enforcement; Semantic Analysis; Service Oriented Computing (SOC); Web Services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Data Engineering Workshop, 2007 IEEE 23rd International Conference on
  • Conference_Location
    Istanbul
  • Print_ISBN
    978-1-4244-0832-0
  • Electronic_ISBN
    978-1-4244-0832-0
  • Type

    conf

  • DOI
    10.1109/ICDEW.2007.4401056
  • Filename
    4401056