Title :
ProActive Caching - A Framework for Performance Optimized Access Control Evaluations
Author :
Kohler, Mathias ; Fies, Robert
Author_Institution :
SAP Res., Karlsruhe, Germany
Abstract :
Users expect that systems react instantly. This is specifically the case for user-centric workflows running in multi-layered enterprise system landscapes which demand fine-grained access control mechanisms and support for dynamic security policies. Thus, efficient evaluation of security policies becomes an important factor for the overall system performance. Caching approaches may help to address this issue. In previous work we introduced ProActive Caching as an approach that consists of two phases: first, in an offline phase, we automatically determine a workflow-specific heuristic for pre-computing and caching access decisions during a process execution. Second, in an online phase, we use the determined heuristic for the cache management. Hence, ProActive Caching provides a framework which is able to pre-compute access decisions based on an offline analysis of the system. In this paper we present a demonstrator for this framework. It comprises a tool for generating the workflow-specific heuristics, as well as a ProActive Caching enabled business process system which uses the generated heuristics for pre-computing access decisions during process execution. An additional performance monitor shows the performance increase of the system.
Keywords :
authorisation; business data processing; cache storage; ProActive Caching; access control; business process system; dynamic security policy; multilayered enterprise system; user-centric workflow; workflow-specific heuristic; Access control; Access Control; Business Process Security; Security Performance Evaluation;
Conference_Titel :
Policies for Distributed Systems and Networks, 2009. POLICY 2009. IEEE International Symposium on
Conference_Location :
London
Print_ISBN :
978-0-7695-3742-9
Electronic_ISBN :
978-0-7695-3742-9
DOI :
10.1109/POLICY.2009.31