首页> 外文会议>European conference on modelling foundations and applications;Conference on software technologies: applications and foundations >Detecting Conflicts Between Data-Minimization and Security Requirements in Business Process Models
【24h】

Detecting Conflicts Between Data-Minimization and Security Requirements in Business Process Models

机译:检测业务流程模型中的数据最小化和安全要求之间的冲突

获取原文

摘要

Detecting conflicts between security and data-minimization requirements is a challenging task. Since such conflicts arise in the specific context of how the technical and organizational components of the target system interact with each other, their detection requires a thorough understanding of the underlying business processes. For example, a process may require anonymous execution for a task that writes data to a secure data storage, where the identity of the writer is needed for the purpose of accountability. To address this challenge, we propose an extension of the BPMN 2.0 business process modeling language to enable: (i) the specification of process-oriented data-minimization and security requirements, (ii) the detection of conflicts between these requirements based on a catalog of domain-independent anti-patterns. The considered security requirements were reused from SecBPMN2, a security-oriented extension of BPMN 2.0, while the data-minimization part is new. SecBPMN2 also provides a graphical query language called SecBPMN2-Q, which we extended to formulate our anti-patterns. We report on feasibility and usability of our approach based on a case study featuring a healthcare management system, and an experimental user study.
机译:检测安全性和数据最小化需求之间的冲突是一项艰巨的任务。由于此类冲突是在目标系统的技术和组织组成部分如何相互影响的特定上下文中发生的,因此对其进行检测需要彻底了解基础业务流程。例如,对于将数据写入安全数据存储的任务,过程可能需要匿名执行,其中出于问责的目的需要写入者的身份。为了应对这一挑战,我们提出了BPMN 2.0业务流程建模语言的扩展,以实现:(i)面向流程的数据最小化和安全性要求的规范,(ii)基于目录检测这些要求之间的冲突。独立于域的反模式。 SecBPMN2(BPMN 2.0的面向安全性的扩展)重新使用了经过考虑的安全性要求,而数据最小化部分是新的。 SecBPMN2还提供了一种称为SecBPMN2-Q的图形查询语言,我们对其进行了扩展以制定反模式。我们基于一个以医疗保健管理系统为特色的案例研究和一个实验性用户研究,报告了我们方法的可行性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号