Secure Workflow Development from Early Requirements Analysis

  • Authors:
  • Magali Séguran;Cédric Hébert;Ganna Frankova

  • Affiliations:
  • -;-;-

  • Venue:
  • ECOWS '08 Proceedings of the 2008 Sixth European Conference on Web Services
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Requirements engineering is being increasingly adopted as a key step in the software development process and so new challenges and possibilities emerge. Designing of web services and developing of business processes and workflows for web services is one of the most thought challenging issues in requirements engineering. The research on web services design is well under way, but the existing design methodologies for web services do not address the issue of developing secure web services, secure business processes and secure workflows. For the purpose of developing secure workflows based on the early requirements analysis, in this work, we propose a refinement methodology and a language that allows the workflow engine to automatically enforce trust and delegation requirements. Those workflows are then to be distributed; the security aspects being enforced dynamically at runtime accordingly to the identified requirements. To make the discussion more concrete, we illustrate the proposal with an e-business banking case study.