Security views for outsourced business processes

  • Authors:
  • Azzedine Benameur;Fabio Massacci;Nataliya Rassadko

  • Affiliations:
  • SAP Research, Security & Trust, Mougins, France;The University of Trento, Povo, Italy;The University of Trento, Povo, Italy

  • Venue:
  • Proceedings of the 2008 ACM workshop on Secure web services
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The workflow of a Virtual Organization is often divided into fragments that are run by different entities having different clearance level or accessibility permissions. Therefore, an important issue is a decomposition of the overall business process into workflow views that can be outsourced to the side of the corresponding contractors. In this paper, we introduce the notion of business process security view and present an algorithm for the automatic derivation of such views from a security specification that may express conditional accessibility based on the actual data flowing across business process. Our solution borrows the idea of virtual views from relational database views. We also discuss an architecture and an implementation for workflow view synchronization.