...
首页> 外文期刊>Computers & Security >Model checking authorization requirements in business processes
【24h】

Model checking authorization requirements in business processes

机译:在业务流程中模型检查授权需求

获取原文
获取原文并翻译 | 示例
           

摘要

Business processes are usually expected to meet high level authorization requirements (e.g., Separation of Duty). Since violation of authorization requirements may lead to economic losses and/or legal implications, ensuring that a business process meets them is of paramount importance. Previous work showed that model checking can be profitably used to check authorization requirements in business processes. However, building formal models that simultaneously account for both the workflow and the access control policy is a time consuming and error-prone activity. In this paper we present a new approach to model checking authorization requirements in business processes that allows for the separate specification of the workflow and of the associated access control policy while retaining the ability to carry out a fully automatic analysis of the business process. To illustrate the effectiveness of the approach we describe its application to a Loan Origination Process subject to an RBAC access control policy featuring conditional permission assignments and delegation.
机译:通常期望业务流程满足高级授权要求(例如,职责分离)。由于违反授权要求可能会导致经济损失和/或法律隐患,因此确保业务流程能够满足这些要求至关重要。先前的工作表明,模型检查可以有益地用于检查业务流程中的授权要求。但是,建立同时考虑工作流和访问控制策略的形式化模型是一项耗时且容易出错的活动。在本文中,我们提出了一种对业务流程中的授权要求进行建模的新方法,该方法允许对工作流程和相关的访问控制策略进行单独的规范,同时保留对业务流程进行全自动分析的能力。为了说明该方法的有效性,我们描述了该方法在基于条件许可分配和委派的RBAC访问控制策略的情况下应用于贷款发起流程的情况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号