首页> 外文会议>Privacy, Security, Trust and the Management of e-Business, 2009. CONGRESS '09 >Formal Analysis of Access Control Policies for Pattern-Based Business Processes
【24h】

Formal Analysis of Access Control Policies for Pattern-Based Business Processes

机译:基于模式的业务流程的访问控制策略的形式分析

获取原文

摘要

We propose formal analysis of access control policies associated with business processes. Formal analysis of such policies enables us to investigate certain properties of interest and determine whether they hold. Discovering whether these policies create the intended effects, especially when the number of policies is increased and often composed, can become complex. In addition, we believe that access control policies must be specified in such a way that their integration into business processes is straightforward. Prior research has focused on formal verification of either access control policies or business processes but not viewed the two as an integrated whole. We show an approach in which access control policies and business processes are described using the same foundational building blocks, consequently, integration of access control policies and business processes is significantly less complex. Furthermore, access control policies can now be described by business patterns, and this description may result in discovery of access control patterns that can be used in the future. Finally, our approach through the use of business patterns is capable of modeling access control policies in the same way an access control model does. In addition, these policies can be specified and extended using rules, and in this respect, are akin to a policy language.
机译:我们建议对与业务流程相关的访问控制策略进行正式分析。对此类政策的形式分析使我们能够调查某些利益属性并确定它们是否成立。发现这些策略是否会产生预期的效果,尤其是当策略数量增加并且经常组合时,可能会变得很复杂。此外,我们认为访问控制策略必须以一种简单的方式集成到业务流程中的方式进行指定。先前的研究侧重于对访问控制策略或业务流程的形式验证,但并未将二者视为一个整体。我们展示了一种使用相同的基础构建块描述访问控制策略和业务流程的方法,因此,访问控制策略和业务流程的集成显着降低了复杂性。此外,现在可以通过业务模式来描述访问控制策略,并且这种描述可能会导致发现将来可以使用的访问控制模式。最后,我们通过使用业务模式的方法能够以与访问控制模型相同的方式对访问控制策略进行建模。此外,可以使用规则来指定和扩展这些策略,并且在这方面类似于策略语言。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号