Title :
Analyzing Workflows in Business Processes for Obstructions due to Authorization Policies
Author :
Spear, Nick ; Malladi, Sreekanth ; Lakkaraju, Sandeep
Author_Institution :
Coll. of Bus. & Inf. Syst., Dakota State Univ., Madison, SD, USA
Abstract :
It is well-known that aligning security policies with business objectives is a difficult task. To address this, we present a new approach to analyze work-flow instances for obstructions due to static and dynamic authorization policies. We give a new algorithm that allows organizations to properly assign users to tasks without the policies causing obstructions (e.g. deadlocks). Our work is novel since we consider loops, conditions and parallelism in workflows, through a new concept called "release" events. We illustrate our approach on some real-world workflows in healthcare and financial industries.
Keywords :
authorisation; business data processing; finance; health care; organisational aspects; workflow management software; business objectives; business processes; dynamic authorization policy; financial industry; healthcare; organizations; real-world workflows ]; security policy; static authorization policy; workflow analysis; Authorization; Board of Directors; Business; Insurance; Medical diagnostic imaging; Medical services;
Conference_Titel :
System Science (HICSS), 2012 45th Hawaii International Conference on
Conference_Location :
Maui, HI
Print_ISBN :
978-1-4577-1925-7
Electronic_ISBN :
1530-1605
DOI :
10.1109/HICSS.2012.112