...
首页> 外文期刊>ACM Transaction on Information and System Security >Dynamic Enforcement of Abstract Separation of Duty Constraints
【24h】

Dynamic Enforcement of Abstract Separation of Duty Constraints

机译:职责限制抽象分离的动态实施

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Separation of Duties (SoD) aims at preventing fraud and errors by distributing tasks and associated authorizations among multiple users. Li and Wang [2008] proposed an algebra (SoDA) for specifying SoD requirements, which is both expressive in the requirements it formalizes and abstract in that it is not bound to a workflow model. In this article, we bridge the gap between the specification of SoD constraints modeled in SoDA and their enforcement in a dynamic, service-oriented enterprise environment. We proceed by generalizing SoDA's semantics to traces, modeling workflow executions that satisfy the respective SoDA terms. We then refine the set of traces induced by a SoDA term to also account for a workflow's control-flow and role-based authorizations. Our formalization, which is based on the process algebra CSP, supports the enforcement of SoD on general workflows and handles changing role assignments during workflow execution, addressing a well-known source of fraud. The resulting CSP model serves as blueprint for a distributed and loosely coupled architecture where SoD enforcement is provisioned as a service. This concept, which we call SoD as a Service, facilitates a separation of concerns between business experts and security professionals. As a result, integration and configuration efforts are minimized and enterprises can quickly adapt to organizational, regulatory, and technological changes. We describe an implementation of SoD as a Service, which combines commercial components such as a workflow engine with newly developed components such as an SoD enforcement monitor. To evaluate our design decisions and to demonstrate the feasibility of our approach, we present a case study of a drug dispensation workflow deployed in a hospital.
机译:职责分离(SoD)旨在通过在多个用户之间分配任务和相关授权来防止欺诈和错误。 Li和Wang [2008]提出了一种用于指定SoD需求的代数(SoDA),该代数在形式化的需求中具有表达性,并且抽象化了,因为它不受工作流程模型的约束。在本文中,我们弥合了在SoDA中建模的SoD约束的规范与其在动态,面向服务的企业环境中的实施之间的差距。我们首先将SoDA的语义概括为跟踪,对满足各自SoDA术语的工作流执行进行建模。然后,我们优化由SoDA术语引起的跟踪集,以考虑工作流的控制流和基于角色的授权。我们基于流程代数CSP的形式化支持在常规工作流程上实施SoD,并在工作流程执行期间处理角色分配更改,从而解决了众所周知的欺诈来源。生成的CSP模型用作分布式和松散耦合体系结构的蓝图,在该体系结构中,SoD强制作为服务提供。这个概念(我们称为SoD即服务)有助于将业务专家和安全专业人员之间的关注点分离。结果,最小化了集成和配置工作,企业可以快速适应组织,法规和技术的变化。我们描述了SoD即服务的实现,该实现将诸如工作流引擎之类的商业组件与诸如SoD实施监视器之类的新开发组件结合在一起。为了评估我们的设计决策并证明我们方法的可行性,我们以在医院中部署的药物分发工作流程为例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号