首页> 外文期刊>Software and systems modeling >A semi-automated BPMN-based framework for detecting conflicts between security, data-minimization, and fairness requirements
【24h】

A semi-automated BPMN-based framework for detecting conflicts between security, data-minimization, and fairness requirements

机译:基于半自动的BPMN的框架,用于检测安全性,数据最小化和公平性要求之间的冲突

获取原文
获取原文并翻译 | 示例

摘要

Requirements are inherently prone to conflicts. Security, data-minimization, and fairness requirements are no exception. Importantly, undetected conflicts between such requirements can lead to severe effects, including privacy infringement and legal sanctions. Detecting conflicts between security, data-minimization, and fairness requirements is a challenging task, as such conflicts are context-specific and their detection requires a thorough understanding of the underlying business processes. For example, a process may require anonymous execution of a task that writes data into a secure data storage, where the identity of the writer is needed for the purpose of accountability. Moreover, conflicts not arise from trade-offs between requirements elicited from the stakeholders, but also from misinterpretation of elicited requirements while implementing them in business processes, leading to a non-alignment between the data subjects' requirements and their specifications. Both types of conflicts are substantial challenges for conflict detection. To address these challenges, we propose a BPMN-based framework that supports: (i) the design of business processes considering security, data-minimization and fairness requirements, (ii) the encoding of such requirements as reusable, domain-specific patterns, (iii) the checking of alignment between the encoded requirements and annotated BPMN models based on these patterns, and (iv) the detection of conflicts between the specified requirements in the BPMN models based on a catalog of domain-independent anti-patterns. The security requirements were reused from SecBPMN2, a security-oriented BPMN 2.0 extension, while the fairness and data-minimization parts are new. For formulating our patterns and anti-patterns, we extended a graphical query language called SecBPMN2-Q. We report on the feasibility and the usability of our approach based on a case study featuring a healthcare management system, and an experimental user study.
机译:要求本质上易于冲突。安全性,数据最小化和公平性要求也不例外。重要的是,这些要求之间的未检测到的冲突可能导致严重影响,包括隐私侵权和法律制裁。检测安全性,数据最小化和公平性要求之间的冲突是一个具有挑战性的任务,因为这种冲突是特定于背景的,他们的检测需要彻底了解潜在的业务流程。例如,过程可能需要匿名执行将数据写入安全数据存储器的任务,其中代表的作者的身份是为了问责制的目的。此外,在利益攸关方引出的要求之间的权衡之间没有产生的冲突,而且来自在业务流程的实施时误解引发要求的误解,导致数据受试者的要求及其规范之间的不一致。两种类型的冲突都是对冲突检测的挑战。为了解决这些挑战,我们提出了一种基于BPMN的框架,支持:(i)考虑安全性,数据最小化和公平要求的业务流程设计,(ii)将这些要求的编码为可重用,域特定模式,( iii)基于这些模式的编码要求和注释的BPMN模型之间的对齐检查(iv)基于域无关的防模式的目录检测BPMN模型中的指定要求之间的冲突。安全要求从SECBMN2重复使用,以安全为导向的BPMN 2.0扩展,而公平和数据最小化部分是新的。为了制定我们的模式和反模式,我们扩展了一种名为SECBPMN2-Q的图形查询语言。我们根据医疗管理系统的案例研究报告了我们方法的可行性和可用性,以及实验用户学习。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号