首页> 外文会议>International Workshop on Formal Aspects in Security and Trust >Model Checking of Security-Sensitive Business Processes
【24h】

Model Checking of Security-Sensitive Business Processes

机译:安全敏感业务流程的模型检查

获取原文

摘要

Security-sensitive business processes are business processes that must comply with security requirements (e.g. authorization constraints). In previous works it has been shown that model checking can be profitably used for the automatic analysis of security-sensitive business processes. But building a formal model that simultaneously accounts for both the workflow and the access control policy is a time consuming and error-prone activity. In this paper we present a new approach to model checking security-sensitive business processes that allows for the separate specification of the workflow and of the associated security policy while retaining the ability to carry out a fully automatic analysis of the process. To illustrate the effectiveness of the approach we describe its application to a version of the Loan Origination Process featuring an RBAC access control policy extended with delegation.
机译:安全敏感的业务流程是必须符合安全要求的业务流程(例如授权约束)。在以前的作用中,已经表明,模型检查可以有利地用于自动分析安全敏感的业务流程。但构建一个同时考虑工作流程和访问控制策略的正式模型是耗时和错误的活动。在本文中,我们提出了一种模拟安全敏感的业务流程的新方法,该过程允许单独规范工作流和相关的安全策略,同时保留对该过程进行全自动分析的能力。为了说明方法的有效性,我们将其应用于其应用于具有委派的RBAC访问控制策略的贷款始发过程的版本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号