DocumentCode :
3117102
Title :
SLA Driven Process Security through Monitored E-contracts
Author :
Tiwari, Ritesh Kumar ; Dwivedi, Vishal ; Karlapalem, Kamalakar
Author_Institution :
HIT-Hyderabad, Hyderabad
fYear :
2007
fDate :
9-13 July 2007
Firstpage :
28
Lastpage :
35
Abstract :
In this work we look into the domain of process security from a service perspective. Most often process security has been enacted through service level agreements (SLA) and business agreements. However, in a multi-party environment such as business process outsourcing (BPO) where processes themselves are offered as a service, the qualitative nature of SLA makes their monitoring quite difficult and their implementation through various restrictions, quite costly. We present our approach wherein we provide security as a process represented using e-Contracts and enacted through workflows. We explore if security too could be offered as a service which could be enacted and monitored by the process participants themselves; thus ensuring more trust. Most of the process based systems employ either Task Based Model (TBAC) or Role Based Model (RBAC) for granting privileges that are needed for executing the individual activities of the workflow. Current approaches are either potentially weak from security perspective, as they grant even those permissions to user which are actually not needed by him for executing the tasks, or they have very high administrative overhead. In this paper, we propose to couple RBAC with TBAC and additionally enforce sequential and temporal constraints over them so that process participants get only ´Need to know information´ with less administrative overhead. In this paper, we propose our extended e-contract framework for security (EC framework), and the architecture of a system which implements it. In the end we present a briefcase study presenting our process security model.
Keywords :
Web services; authorisation; business data processing; contracts; outsourcing; SLA driven process security; business process outsourcing; e-contract; role-based access control; service level agreement; task-based access control; Access control; Authorization; Contracts; Data security; Guidelines; Humans; Information security; Monitoring; Outsourcing; Permission;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services Computing, 2007. SCC 2007. IEEE International Conference on
Conference_Location :
Salt Lake City, UT
Print_ISBN :
0-7695-2925-9
Type :
conf
DOI :
10.1109/SCC.2007.109
Filename :
4278634
Link To Document :
بازگشت