首页> 外文会议>International Conference on System Science and Engineering >A Method to Ensure Compliance with Attribute and Role Based Access Control Policy for Executing BPMN Models
【24h】

A Method to Ensure Compliance with Attribute and Role Based Access Control Policy for Executing BPMN Models

机译:一种确保执行BPMN模型时遵守基于属性和角色的访问控制策略的方法

获取原文
获取外文期刊封面目录资料

摘要

The stringent control of access rights during business processes execution is an important technique to ensure systems security. Business processes are often designed and operated based on models represented by domain-specific languages, such as BPMN. Moreover, access control policies are often studied and specified based on access control models, such as Role-based Access Control (RBAC) and Attribute-based Access Control (ABAC). These security techniques have several challenges that need to be addressed, such as (1) ensuring consistency of RBAC/ABAC policy specifications and (2) ensuring compliance with RBAC/ABAC policies when executing a business process. In this paper, we propose using a metamodeling technique to take advantage of UML and OCL’s expressive power in order to facilitate validation and verification of RBAC/ABAC policies. Within our approach, the RBAC metamodel is extended so that ABAC constraints for complex business rules could be captured and checked. We build a support tool by incorporating Activiti (the support tool for specifying and implementing BPMN models) with USE (UML-based Specification Environment). The proposed method is experimented and evaluated for the process of liquidating the individual teaching contracts of a training management system.
机译:在业务流程执行期间严格控制访问权限是确保系统安全的一项重要技术。业务流程通常基于特定领域语言(如BPMN)表示的模型进行设计和操作。此外,访问控制策略通常基于访问控制模型进行研究和指定,如基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC)。这些安全技术有几个需要解决的挑战,例如:(1)确保RBAC/ABAC策略规范的一致性;(2)确保在执行业务流程时遵守RBAC/ABAC策略。在本文中,我们建议使用元建模技术来利用UML和OCL的表达能力,以方便RBAC/ABAC策略的验证。在我们的方法中,RBAC元模型得到了扩展,从而可以捕获和检查复杂业务规则的ABAC约束。我们通过将Activiti(用于指定和实现BPMN模型的支持工具)与USE(基于UML的规范环境)结合起来,构建了一个支持工具。针对培训管理系统的个别教学合同的清算过程,对所提出的方法进行了实验和评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号